A database associated with an Advance Passenger Information System (APIS) was found to be publicly accessible online due to a series of security misconfigurations. This exposed database contained more than 220 million records belonging to airline passengers and crew members.
The exposed data includes sensitive personal details such as names, dates of birth, nationalities, passport numbers, document expiration dates, and issuing countries. Additionally, flight-related information like flight numbers, dates, airlines, departure/destination airports, seat assignments, and baggage references were also compromised. The records cover a period from January 2017 to April 2026.
Kinryū Labs discovered the Elasticsearch cluster, named 'pax-info', on June 3 during research into ransomware activity. The cluster, totaling 107 GB, contained 210,318,069 passenger records and 10,465,631 crew records. Researchers confirmed the data's legitimacy by cross-referencing it with their own travel information. The database appears linked to a Vietnamese organization, hosted within Viettel-assigned IP space in Hanoi.
The exposed records could affect travelers of numerous nationalities who flew to, from, or through Vietnam during the nine-year period. While the figures represent travel records rather than unique individuals, the sheer volume and sensitive nature of the data present a significant privacy and security risk for millions of people globally.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
An Advance Passenger Information System (APIS) database, containing over 220 million passenger and crew records, was publicly accessible due to security misconfigurations. This exposure includes passport numbers and flight details for travelers to, from, or through Vietnam from 2017 to 2026, posing a significant privacy risk for a large number of individuals.