Latest News (EN)

Vietnam breach leaks 220 million passenger records online

Aeroporto americano
Photo: Aeroporto americano - lechatnoir/istock
Share

An Advance Passenger Information System database containing over 220 million confidential logs of airline passengers and flight crew members sat exposed on the open internet on 8 September 2026 at 03:35 because of multiple technical configuration errors tied to an entity in Vietnam.

Such platforms operate worldwide to collect passenger identities, passport numbers, and flight itineraries submitted by commercial airlines ahead of border crossings. The protocol is mandatory.

The unprotected trove spans flight activity documented between January 2017 and April 2026, catching foreign travelers who arrived, departed, or made layovers inside Vietnamese territory during that window.

Flight registries remained open to the web for nine years

Security analysts at Kinryū Labs located the unsecured Elasticsearch cluster on 3 June while conducting regular scans of public servers to track ransomware campaigns. The find occurred during standard infrastructure monitoring.

Designated as pax-info, the structure held 29 separate indices totaling roughly 107 gigabytes of raw data. Two primary tables stored the bulk of the cache, holding 210,318,069 passenger documents and 10,465,631 crew records. Across the entire cluster, the total volume reached 220,783,700 individual entries.

The exposed machine resided within an IP address range assigned to telecommunications provider Viettel in the city of Hanoi, though researchers did not publicly identify the specific Vietnamese agency operating the server.

The data files listed full legal names, dates of birth, gender, nationalities, passport codes, document expiration dates, and issuing authorities for each traveler. The repository held private personal records.

The compromised system also exposed aircraft tail numbers, operational dates, carrier names, departure, transit, and arrival terminals, assigned seating positions, checked baggage tracking tags, and precise schedules covering scheduled, estimated, and actual flight times.

Random inspections of the repository revealed personal profiles belonging to citizens of China, Canada, South Korea, and New Zealand among the stored entries. Multiple other nationalities appeared in the logs.

Although the repository lacks a full percentage breakdown by country, the records span numerous international air carriers operating across Europe, the Middle East, and the Asia-Pacific region, indicating that travelers from nearly every continent passed through the database over nine years.

Investigators from Kinryū Labs verified the authenticity of the records by searching the database and finding their own past travel dossiers for trips into Vietnam. That direct query validated the leak.

The published figures reflect total flight movements rather than unique individual persons, meaning frequent travelers appear multiple times across the database.

Chained configuration errors exposed server infrastructure

Technicians at Kinryū Labs reported that they accessed the directory by stringing together two distinct configuration errors. Those security gaps remained live inside the digital environment.

Share

More news in Latest News (EN)

See more