Close Menu
NCIJ Network NCIJ Network
    What's Hot

    French AI startup Mistral raises 3 billion euros after latest funding

    September 8, 2026

    Instagram users face ransom demands over fake copyright claims

    September 8, 2026

    220 million traveler records exposed in Vietnam-linked APIS leak

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • French AI startup Mistral raises 3 billion euros after latest funding
    • Instagram users face ransom demands over fake copyright claims
    • 220 million traveler records exposed in Vietnam-linked APIS leak
    • Brazilian Banks Expand Crypto Offerings as Regulation Takes Hold
    • Youth clubs, trade unions, pubs: here’s how Burnham can fix Britain’s social recession | Gordon Brown
    • US Open: Zheng in 5-0 comeback; Gauff, Rybakina, Zverev also in quarters | Tennis
    • Eiffel Tower shut by staff strike over female workers being moved for religious visit
    • Police seek to identify protesters behind Portsmouth anti-migrant disorder
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    220 million traveler records exposed in Vietnam-linked APIS leak

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it.

    Advance Passenger Information Systems are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country.

    The exposed records span January 2017 to April 2026 and could involve travelers of many nationalities who flew to, from, or through Vietnam during that period.

    Nine years of passenger and crew data

    Kinryū Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity.

    The cluster, named ‘pax-info’, contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries.

    According to Kinryū Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated the system.

    The exposed information included passengers’ and crew members’ names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries.

    Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems.

    Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others.

    A sample table from the database
    Sample database records showing passenger names, nationalities, passport information, and flight details

    (Kinryū Labs)

    While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

    Kinryū Labs verified that the information was legitimate by matching records in the database against its researchers’ own travel to Vietnam.

    The figures represent travel records rather than unique individuals. Passengers and crew members who flew multiple times may therefore appear repeatedly in the database.

    Database accessible through chained misconfigurations

    Kinryū Labs told BleepingComputer that it reached the database by chaining two misconfigurations.

    From the open internet, the endpoint returned an HTTP 401 “Unauthorized” response, preventing direct access to the database. However, a cloud-based path enabled researchers to reach the cluster, which then accepted default credentials.

    Internet intelligence platform FOFA first recorded the host and port in October 2022 and identified the service as a database in July 2023. However, Kinryū Labs could not determine when the passenger data first became retrievable through the second access path.

    As a result, while the records themselves span more than nine years, the actual length of the exposure is unknown.

    Kinryū Labs said it reported the issue to Vietnamese authorities, airlines represented in the database, and national computer emergency response teams beginning June 3. The researchers said access to the database was remediated on June 8.

    An authenticated email reviewed by BleepingComputer shows that Singapore Airlines’ security team helped coordinate the response, informing Kinryū Labs on June 8 that it had “engaged the relevant parties” and “taken steps to contain the issue.” Singapore Airlines did not provide an additional comment to BleepingComputer.

    The findings shared with BleepingComputer identify several major airlines whose passenger records appeared in the database. However, there is no indication that the airlines operated the exposed system or that their own networks were compromised.

    Changi Airport Group, which manages and operates Singapore’s Changi Airport, told BleepingComputer that it had investigated the matter but declined to comment.

    BleepingComputer also contacted Vietnamese authorities well in advance of publication but received no response.

    It remains unclear whether the database was downloaded, sold, ransomed, or otherwise exploited by malicious actors before it was secured. Kinryū Labs said it found no ransom notes or unfamiliar indices on the cluster and could not identify the dataset being offered for sale online.

    However, without access to server logs, the researchers could not conclusively determine whether anyone had copied the data.

    Kinryū Labs expects to publish additional technical findings on its blog later this week.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    APIs exposed leak Million records traveler Vietnamlinked
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    OpenAI Agents Hijack Another Victim Website

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    Tether-backed crypto exchange freezes withdrawals after $7 million leaves custody

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    French AI startup Mistral raises 3 billion euros after latest funding

    September 8, 2026

    Instagram users face ransom demands over fake copyright claims

    September 8, 2026

    220 million traveler records exposed in Vietnam-linked APIS leak

    September 8, 2026

    Brazilian Banks Expand Crypto Offerings as Regulation Takes Hold

    September 8, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    French AI startup Mistral raises 3 billion euros after latest funding

    September 8, 2026

    Instagram users face ransom demands over fake copyright claims

    September 8, 2026

    220 million traveler records exposed in Vietnam-linked APIS leak

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.