By T2 Editors10 hours ago

Summary

More than 220 million passenger and crew records were left exposed in a misconfigured Advance Passenger Information System database in Vietnam, revealing passport numbers, full itineraries, and seat assignments dating from January 2017 to April 2026. The discovery by security researchers—and subsequent lockdown—did not come with any evidence of unauthorized access, but the sheer volume of identity-rich data makes the exposure a severe fraud risk for anyone who flew through Vietnam during that window.

The database operator remains unidentified, and investigators have not yet determined whether threat actors copied the data before it was secured. Travelers should immediately activate credit monitoring and treat any message that references real flight details as a potential phishing attempt.

A poorly secured passenger-screening system in Vietnam has handed criminals a potential nine-year archive of identity data, exposing the passport numbers, travel documents, and complete itineraries of an estimated 220 million travelers. The breach, discovered by security research firm Kinryu Labs on June 3, 2026, stems from an Advance Passenger Information System (APIS) database that was left open to the internet through a series of cloud misconfigurations.

The exposed cluster contained 29 indices weighing roughly 107 GB, with a single index holding more than 210 million passenger records and another carrying 10.4 million crew records. The files spanned from January 2017 to April 2026, meaning frequent flyers are likely recorded multiple times across different trips. The data fields included passport numbers, expiration dates, issuing country, sex, nationality, name, date of birth, airline, departure and destination airports, transit airports, seat assignments, and baggage references.

The scope is vast. Records referenced airlines across Asia-Pacific, Europe, and the Middle East, and included Canadian, Chinese, South Korean, and New Zealand nationals. Because the system handles border-control data, the credentials leaked are not just contact details—they are the exact documents used for international travel, making them ideal for identity theft and highly believable social engineering. The database was locked down on June 8, 2026, five days after the researchers alerted Vietnamese authorities, the country’s CERT, and impacted airlines. No dark-web sale or hacker claim has surfaced, but forensic logs have not been publicly reviewed, leaving the true compromise status unknown.

How the exposure unfolded

The leak originated from an Elasticsearch cluster hosted on Viettel-assigned IP space in Hanoi, Vietnam. Although the cluster was not directly reachable from the public internet, a cloud-based alternative route allowed access, and the system accepted default credentials. Once inside, researchers found a fully browsable archive of APIS data—the standard mechanism airlines use to transmit passenger and crew details to destination-country authorities before departure or arrival.

Unlike a typical commercial data breach, this incident sits at the intersection of data privacy and physical security. The records are not just marketing profiles but the actual identity documents used at border crossings. The inclusion of seat assignments and complete itineraries adds a dangerous layer: a fraudster could reference a traveler’s real flight to make a scam call or email sound authenticated.

Timeline of the APIS database exposure
Date Event Impact Status
January 2017 – April 2026 Unsecured database stores APIS records 220M+ passenger and crew records exposed Exposure window closed
June 3, 2026 Kinryu Labs discovers misconfiguration Researchers report to Vietnamese authorities, CERT, and airlines Discovery phase
June 8, 2026 Database locked down Public access blocked; forensic investigation status unclear Containment completed
Ongoing No confirmed misuse or dark-web sale Travelers remain at risk of identity theft and phishing Monitoring needed
ATC

Flight deals most people never see

Our AI monitors 150+ airlines for pricing anomalies that traditional search engines miss. Air Traveler Club members save $650 per trip per person on average: see how it works.


Each deal saves 40–80% vs. regular fares:

Superdeals preview

Why this breach is different for frequent flyers

Large travel-data exposures rarely disrupt flight operations, but they become long-tail fraud stories. The APIS leak is especially dangerous for business travelers and elite status holders because they are more likely to have dozens of records in the archive—each trip creates a new entry. A fraudster who pulls a traveler’s real seat assignment and route from 2022 can craft a phishing email that cites that exact flight, bypassing the skepticism that generic scams trigger.

The nine-year exposure window also means many travelers have no practical way to recall every transit through Vietnam. Even a single connection in Hanoi or Ho Chi Minh City could have generated a record. The immediate priority is not cancelling flights but shoring up identity defenses: credit report freezes, transaction alerts, and a zero-trust approach to unsolicited messages that reference past travel. The American Express identity theft protection guide recommends enabling account alerts and app notifications, while its Canadian counterpart stresses fraud alerts and direct credit-bureau contact after a suspected identity theft.

What the 220M-record exposure means for your travel security

This is not a breach that can be resolved with a password change. The data that leaked is the permanent, government-issued identity you use to cross borders, and it will remain valid for years. The initial response should focus on surveillance and early detection, not panic.

  • Enable transaction alerts on every payment card and bank account. Most issuers allow you to set instant notifications for any transaction; this is the fastest way to spot unauthorized activity before it escalates.
  • Treat any message referencing your past travel as suspect. Fraudsters may use real seat assignments, flight numbers, or baggage references to build trust. Verify directly with the airline or agency using official contact channels—never respond to the message itself.
  • Freeze credit files and place a fraud alert. A credit freeze prevents new accounts from being opened in your name, while a fraud alert requires extra identity checks. Both are free and can be lifted temporarily when you need to apply for credit.
  • Monitor your email and phone for credential-stuffing attempts. If the APIS data includes email addresses or phone numbers alongside passport details, attackers may try to access other accounts using that information.
  • Document and report any suspicious activity immediately. File a report with local law enforcement, your national data-protection authority, and the credit bureaus. A formal record can help dispute fraudulent charges or accounts later.

Reporting by

T2.0 Editors

Since 2010, we've tracked global aviation markets across four continents, monitoring 150+ airlines and their route networks, fare structures, and seasonal dynamics. Our team delivers daily aviation intelligence — combining technology with on-the-ground market knowledge.

FAQ

Was my data definitely exposed?

There is no public lookup tool to confirm individual exposure, but if you flew to, from, or through Vietnam at any time between January 2017 and April 2026, your passport details and itinerary were likely in the archive. Because the system stored records from multiple airlines, even a single transit could have generated a record.

What is the first thing I should do?

Activate transaction alerts on all your payment cards and bank accounts, and then place a free credit freeze with the three major credit bureaus. This prevents new accounts from being opened in your name without your explicit permission.