Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Vietnam-linked APIS leak exposed 220 million traveler records

An Advance Passenger Information System (APIS) database exposed 220 million passenger and crew records online. The records span January 2017 to April 2026 and include names, dates of birth, nationalities, passport or travel-document numbers, and flight details.

Kinryū Labs discovered the Elasticsearch cluster on June 3 while researching exposed databases. Named “pax-info,” the cluster contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries.

According to Kinryū Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated it. The data also included airlines, flight numbers and dates, airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times.

Researchers said they reached the database by chaining two misconfigurations. The public endpoint returned HTTP 401 “Unauthorized,” but a cloud-based path led to the cluster, which accepted default credentials. The records represent trips rather than unique people, so repeat travelers may appear more than once.

Kinryū Labs reported the issue to Vietnamese authorities, airlines, and national computer emergency response teams beginning June 3. The researchers said access was remediated on June 8. They could not determine whether anyone copied or otherwise exploited the data before it was secured.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.