Summary
More than 220 million passenger and crew records were left exposed in a misconfigured Advance Passenger Information System database in Vietnam, revealing passport numbers, full itineraries, and seat assignments dating from January 2017 to April 2026. The discovery by security researchers—and subsequent lockdown—did not come with any evidence of unauthorized access, but the sheer volume of identity-rich data makes the exposure a severe fraud risk for anyone who flew through Vietnam during that window.
The database operator remains unidentified, and investigators have not yet determined whether threat actors copied the data before it was secured. Travelers should immediately activate credit monitoring and treat any message that references real flight details as a potential phishing attempt.
A poorly secured passenger-screening system in Vietnam has handed criminals a potential nine-year archive of identity data, exposing the passport numbers, travel documents, and complete itineraries of an estimated 220 million travelers. The breach, discovered by security research firm Kinryu Labs on June 3, 2026, stems from an Advance Passenger Information System (APIS) database that was left open to the internet through a series of cloud misconfigurations.
The exposed cluster contained 29 indices weighing roughly 107 GB, with a single index holding more than 210 million passenger records and another carrying 10.4 million crew records. The files spanned from January 2017 to April 2026, meaning frequent flyers are likely recorded multiple times across different trips. The data fields included passport numbers, expiration dates, issuing country, sex, nationality, name, date of birth, airline, departure and destination airports, transit airports, seat assignments, and baggage references.
The scope is vast. Records referenced airlines across Asia-Pacific, Europe, and the Middle East, and included Canadian, Chinese, South Korean, and New Zealand nationals. Because the system handles border-control data, the credentials leaked are not just contact details—they are the exact documents used for international travel, making them ideal for identity theft and highly believable social engineering. The database was locked down on June 8, 2026, five days after the researchers alerted Vietnamese authorities, the country’s CERT, and impacted airlines. No dark-web sale or hacker claim has surfaced, but forensic logs have not been publicly reviewed, leaving the true compromise status unknown.
How the exposure unfolded
The leak originated from an Elasticsearch cluster hosted on Viettel-assigned IP space in Hanoi, Vietnam. Although the cluster was not directly reachable from the public internet, a cloud-based alternative route allowed access, and the system accepted default credentials. Once inside, researchers found a fully browsable archive of APIS data—the standard mechanism airlines use to transmit passenger and crew details to destination-country authorities before departure or arrival.
Unlike a typical commercial data breach, this incident sits at the intersection of data privacy and physical security. The records are not just marketing profiles but the actual identity documents used at border crossings. The inclusion of seat assignments and complete itineraries adds a dangerous layer: a fraudster could reference a traveler’s real flight to make a scam call or email sound authenticated.
| Date | Event | Impact | Status |
|---|---|---|---|
| January 2017 – April 2026 | Unsecured database stores APIS records | 220M+ passenger and crew records exposed | Exposure window closed |
| June 3, 2026 | Kinryu Labs discovers misconfiguration | Researchers report to Vietnamese authorities, CERT, and airlines | Discovery phase |
| June 8, 2026 | Database locked down | Public access blocked; forensic investigation status unclear | Containment completed |
| Ongoing | No confirmed misuse or dark-web sale | Travelers remain at risk of identity theft and phishing | Monitoring needed |
Flight deals most people never see
Our AI monitors 150+ airlines for pricing anomalies that traditional search engines miss. Air Traveler Club members save $650 per trip per person on average: see how it works.
Each deal saves 40–80% vs. regular fares:
Why this breach is different for frequent flyers
Large travel-data exposures rarely disrupt flight operations, but they become long-tail fraud stories. The APIS leak is especially dangerous for business travelers and elite status holders because they are more likely to have dozens of records in the archive—each trip creates a new entry. A fraudster who pulls a traveler’s real seat assignment and route from 2022 can craft a phishing email that cites that exact flight, bypassing the skepticism that generic scams trigger.
The nine-year exposure window also means many travelers have no practical way to recall every transit through Vietnam. Even a single connection in Hanoi or Ho Chi Minh City could have generated a record. The immediate priority is not cancelling flights but shoring up identity defenses: credit report freezes, transaction alerts, and a zero-trust approach to unsolicited messages that reference past travel. The American Express identity theft protection guide recommends enabling account alerts and app notifications, while its Canadian counterpart stresses fraud alerts and direct credit-bureau contact after a suspected identity theft.
What the 220M-record exposure means for your travel security
This is not a breach that can be resolved with a password change. The data that leaked is the permanent, government-issued identity you use to cross borders, and it will remain valid for years. The initial response should focus on surveillance and early detection, not panic.
- Enable transaction alerts on every payment card and bank account. Most issuers allow you to set instant notifications for any transaction; this is the fastest way to spot unauthorized activity before it escalates.
- Treat any message referencing your past travel as suspect. Fraudsters may use real seat assignments, flight numbers, or baggage references to build trust. Verify directly with the airline or agency using official contact channels—never respond to the message itself.
- Freeze credit files and place a fraud alert. A credit freeze prevents new accounts from being opened in your name, while a fraud alert requires extra identity checks. Both are free and can be lifted temporarily when you need to apply for credit.
- Monitor your email and phone for credential-stuffing attempts. If the APIS data includes email addresses or phone numbers alongside passport details, attackers may try to access other accounts using that information.
- Document and report any suspicious activity immediately. File a report with local law enforcement, your national data-protection authority, and the credit bureaus. A formal record can help dispute fraudulent charges or accounts later.
Reporting by
T2.0 Editors
Since 2010, we've tracked global aviation markets across four continents, monitoring 150+ airlines and their route networks, fare structures, and seasonal dynamics. Our team delivers daily aviation intelligence — combining technology with on-the-ground market knowledge.
FAQ
Was my data definitely exposed?
There is no public lookup tool to confirm individual exposure, but if you flew to, from, or through Vietnam at any time between January 2017 and April 2026, your passport details and itinerary were likely in the archive. Because the system stored records from multiple airlines, even a single transit could have generated a record.
What is the first thing I should do?
Activate transaction alerts on all your payment cards and bank accounts, and then place a free credit freeze with the three major credit bureaus. This prevents new accounts from being opened in your name without your explicit permission.
Read more
SEC bought 1 billion airline records to track travelers without warrant, sparking outrage
The Securities and Exchange Commission purchased warrantless access to more than one billion airline booking records from the Airlines Reporting Corporation's Travel Intelligence Program — a database containing passenger names, credit card numbers, flight details, and itineraries including trips entirely outside the United States. The civil regulator used a daily alert system that flagged individuals against agency watchlists, requesting between one and 25 alerts each day. Though the program was shuttered by the end of 2025 after lawmaker pressure, the newly revealed scale of surveillance leaves urgent questions about what data was amassed and who else had access. Travelers who booked through agencies or third-party portals were directly exposed, and the SEC's FOIA office still accepts Privacy Act requests to check individual records.
Google acquires 600 million internal Spirit Airlines messages for $10M — sparking privacy debate
Google has acquired roughly 600 million internal messages from defunct ultra-low-cost carrier Spirit Airlines for $10 million in a bankruptcy auction, paying approximately 1.7 cents per message. The dataset, encompassing 100 million employee emails and 500 million Microsoft Teams chats, will be de-identified and used for AI model training, marking one of the first instances of a defunct airline's corporate memory being monetized for technology development. The transaction, which excludes customer profiles and credit card numbers, awaits approval from a federal bankruptcy judge on August 19, 2026. It tests whether internal employee communications can be legally repurposed after corporate failure, even with promises of anonymization.
India unveils Fast Track Immigration at 13 airports, slashing wait times for pre-verified travelers
India's Fast Track Immigration-Trusted Traveller Programme now operates at 13 airports including Delhi, Mumbai, and Bengaluru, allowing pre-verified Indian nationals and OCI holders to clear immigration through biometric e-gates in seconds rather than waiting 30-plus minutes in standard queues. Nearly 300,000 passengers have enrolled in the free program since its June 2024 launch, with expansion to five additional airports completed in September 2025. The program requires online registration at the official government portal, biometric enrollment at designated counters, and processing takes up to 30 days. Membership remains valid for 10 years or until passport expiration, whichever comes first.
Federal Court upholds No Fly List, ruling right to travel does not extend to air travel
The D.C. Circuit Court of Appeals ruled on April 14, 2026, that the constitutional right to travel does not extend to air travel, upholding the TSA No Fly List and the Department of Homeland Security's redress process despite offering no opportunity to confront evidence. Travelers on the list—including those holding $8,000+ business class tickets or 100,000+ point awards—face immediate boarding denials across all cabin classes with no automatic airline rebooking or refund rights. The ruling reverses a decade of federal court precedent requiring due process reforms. Premium travelers with existing bookings must submit a DHS Traveler Redress Inquiry Program [https://www.dhs.gov/dhs-trip] request within 24-48 hours to protect itineraries, as processing takes 6-12 months with no expedited option for elite status holders.
Congress probes 8 US airlines over ‘surveillance pricing’ tactics using AI and personal data
The House Energy and Commerce Committee has given eight major U.S. airlines until August 25, 2026 to disclose whether artificial intelligence and personal consumer data — including browsing history, device type, and geographic location — help set the fare shown to each individual traveler. The formal inquiry, led by Ranking Member Frank Pallone Jr., marks the first time Congress has demanded that the entire major airline industry account for so-called surveillance pricing, a practice the Federal Trade Commission confirmed in a January 2025 study relied on precise location and browser history to target prices. The letters are requests, not subpoenas, but the responses could trigger airline-specific disclosure rules or enforcement action. The probe follows a viral April incident in which JetBlue’s social team advised a customer to clear cookies to lower a fare before deleting the reply — a glimpse of behavioral pricing logic now at the center of two federal class actions.
JetBlue accused of selling passenger data to set airfares, sparking ‘surveillance pricing’ lawsuit
A proposed class action lawsuit filed April 22, 2026, in Brooklyn federal court accuses JetBlue Airways of deploying digital trackers to collect passengers' personal data — browsing history, device type, location — and sharing it with third parties to adjust ticket prices in real time without consent. Plaintiff Andrew Phillips alleges the practice, known as "surveillance pricing," means two travelers searching the same flight simultaneously could see entirely different fares. JetBlue denies the allegations, maintaining fares are set by demand and seat inventory alone. A separate FTC investigation published in January 2026 found retailers broadly using personal data for individualized pricing, lending regulatory weight to the complaint. The lawsuit follows a viral social media exchange in which JetBlue advised a passenger to clear cookies to lower a fare — then deleted the post. That single reply is now central to the case.

