Breaking
SecurityDeveloping Story

APIS Leak Exposes 220M Travel Records

A misconfigured Vietnamese APIS database exposed 220M passenger and crew records, including passport data.

··5 hours ago·3 min read
empty gray airport seats during daytime
Photo by Dennis Gecaj on Unsplash

Security researchers have uncovered a massive data exposure affecting air travelers worldwide. A database linked to Vietnam, holding more than 220 million passenger and crew records, was accessible online due to a chain of security misconfigurations. The discovery raises serious concerns about the safety of personal and travel data collected by national border control systems.

The Discovery of a Decade of Data

Kinryū Labs, a security research firm, found the exposed Elasticsearch cluster on June 3 while scanning for vulnerable databases during ransomware-focused research. The cluster, named 'pax-info', contained 29 indices and roughly 107 GB of data. The two main indices held 210,318,069 passenger records and 10,465,631 crew records, totaling 220,783,700 entries.

According to Kinryū Labs, the data spans from January 2017 to April 2026, covering nearly a decade of travel information. The records could involve travelers of many nationalities who flew to, from, or through Vietnam during that period.

What Information Was Exposed

The exposed database included sensitive personal details such as passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. It also contained travel specifics like flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times—standard APIS data.

Sample records reviewed by BleepingComputer showed travelers of Korean, Chinese, Canadian, and New Zealand nationalities, among others. The data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East, meaning the leak could affect people from virtually anywhere who visited or transited through Vietnam.

Kinryū Labs verified the data's legitimacy by matching records against its own researchers' travel to Vietnam. The figures represent travel records, not unique individuals; frequent flyers might appear multiple times.

How the Database Was Left Open

The exposure stemmed from chained misconfigurations. From the open internet, the endpoint returned an HTTP 401 "Unauthorized" response, blocking direct access. However, a cloud-based path allowed researchers to reach the cluster, which then accepted default credentials.

Internet intelligence platform FOFA first logged the host and port in October 2022, identifying the service as a database in July 2023. Kinryū Labs could not determine when the passenger data first became accessible through the second path, so the full exposure window remains unknown.

Response and Remediation

Kinryū Labs reported the issue to Vietnamese authorities, affected airlines, and national computer emergency response teams starting June 3. The researchers said access was remediated on June 8.

Singapore Airlines' security team assisted in the response, confirming on June 8 that it had "engaged the relevant parties" and "taken steps to contain the issue." The airline did not offer further comment. Changi Airport Group, which operates Singapore's Changi Airport, investigated but declined to comment. Vietnamese authorities did not respond to BleepingComputer's inquiries.

Uncertain Scope of Exploitation

Whether the database was downloaded, sold, ransomed, or otherwise exploited before being secured remains unclear. Kinryū Labs found no ransom notes or unfamiliar indices on the cluster and could not identify the data for sale online. However, without server logs, the researchers couldn't conclusively determine if anyone had copied the data.

Implications for Travelers and Airlines

The leak poses significant risks. Passport numbers and personal details can be used for identity theft, fraud, and targeted scams. Travelers who flew to, from, or through Vietnam since 2017 may be affected. Airlines represented in the database face reputational damage and potential regulatory scrutiny, even though there's no indication they operated the exposed system.

This incident underscores the importance of securing APIS databases, which are critical for border control but contain highly sensitive data. Organizations must ensure proper configuration, strong credentials, and regular security audits to prevent such exposures.

Kinryū Labs plans to publish additional technical findings on its blog later this week.

Why This Matters

The exposure of 220 million records could have far-reaching consequences for data privacy and security. It suggests that even systems designed to protect national borders can be compromised by basic misconfigurations. For travelers, this means their personal information may be at risk without their knowledge. For the aviation industry and governments, it highlights the need for robust security measures and prompt incident response to prevent such lapses in the future.

#data breach#apis#vietnam#travel records#security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories