220 Million Traveler Records Leaked in Vietnam-Linked APIS Breach
220 million traveler records exposed in Vietnam-linked APIS leak
Overview of the Breach
A database containing over 220 million passenger and crew records, including passport details and flight information, was publicly accessible via a series of security misconfigurations. The system, linked to a Vietnamese entity, was identified by researchers who noted the exposure spanned from January 2017 to April 2026.
Understanding APIS
Advance Passenger Information Systems (APIS) are utilized globally to collect traveler data, such as identity, passport, and flight details, prior to arrival or departure from a country. The compromised records encompassed individuals from multiple nationalities who traveled to, from, or through Vietnam during the nine-year period.
Discovery by Kinry Labs
Kinry Labs discovered an Elasticsearch cluster named \\\”pax-info\\\” on June 3 while investigating exposed databases related to ransomware activity. The cluster contained 29 indices and approximately 107 GB of data, with two primary indices holding 210,318,069 passenger records and 10,465,631 crew records.
Details of Exposed Data
The data was hosted within Viettel-assigned IP space in Hanoi, though the exact organization operating the system remains unconfirmed. Exposed information included names, dates of birth, gender, nationalities, passport or travel document numbers, expiration dates, and issuing countries. Travel data such as flight numbers, dates, airlines, departure and destination airports, transit points, seat assignments, baggage references, and scheduled, estimated, and actual flight times were also present.
How the Data Was Accessed
The database was accessed through a combination of misconfigurations. Researchers noted that an initial endpoint returned an HTTP 401 \\\”Unauthorized\\\” response, but a secondary access path allowed retrieval of data. The host and port were first recorded by the Internet intelligence platform FOFA in October 2022, with the service identified as a database in July 2023.
Response and Remediation
Kinry Labs reported the issue to Vietnamese authorities, airlines represented in the database, and national computer emergency response teams starting June 3. Access to the database was remediated by June 8. A review by investigators indicated that Singapore Airlines’ security team coordinated the response, confirming on June 8 that \\\”relevant parties\\\” had been engaged and \\\”steps to contain the issue\\\” were taken.
“relevant parties” had been engaged and “steps to contain the issue” were taken.
Broader Implications
The findings highlight several major airlines whose passenger data appeared in the database, though there is no evidence the airlines operated the system or that their networks were compromised. Changi Airport Group, which manages Singapore’s Changi Airport, investigated the matter but declined to comment. Vietnamese authorities were contacted but did not respond.
Additional Research Findings
The researchers could not determine if the data was copied due to lack of server logs. Kinry Labs plans to release additional technical details on its blog. A separate study, The Blue Report 2026, analyzed 338 million simulations across customer environments, revealing that 37% of attacker actions with valid credentials were blocked. The incident underscores the risks of misconfigured systems and the importance of proactive security measures in protecting sensitive traveler data.
