Travel Market News is an independent publication covering the business of travel — aviation, hospitality, tourism, destinations and the technology reshaping how the world moves.

Vietnam-Linked Leak Exposes 220M Passenger Records

Vietnam-Linked Leak Exposes 220M Passenger Records
Share
An open pax-info database exposed 220.8M Vietnam-linked passenger records with passport numbers and itineraries; secured June 8 after Kinryu Labs' report. What flyers should do.

Cover image: Noi Bai International Airport terminal in Hanoi, Vietnam — photo by InterEdit88, CC0, via Wikimedia Commons.

An open database holding 220.8 million passenger and crew records linked to Vietnam was exposed on the public internet, including passport numbers, birth dates and nine years of flight itineraries. The Elasticsearch cluster, nicknamed pax-info, held about 107GB of data across 29 indices covering January 2017 to April 2026, and was secured on June 8 only after security researchers reported it to Vietnamese authorities and affected airlines, according to reports published September 8 by SecurityAffairs and BetaNews.

Anyone who flew to, from or through Vietnam on the involved carriers during that window may be affected. The exposed fields read like a checklist for identity fraud: full names, dates of birth, sex, nationalities, passport numbers with expiry dates and issuing countries, plus flight numbers, routes, transit points, seat numbers and baggage references. Researchers could not determine whether anyone copied the data before it was locked down.

What was exposed in the Vietnam APIS leak?

The database appears to be an Advance Passenger Information System feed: the identity and flight data airlines collect from carriers before arrival or departure. Two indices did most of the damage, with 210,318,069 traveller entries and 10,465,631 crew entries. The 220 million figure counts trip records rather than distinct people, since frequent flyers appear many times, but it still spans nine years of arrivals, departures and transits involving Vietnam across airlines from Asia-Pacific, Europe and the Middle East. Sample entries included Korean, Chinese, New Zealand and Canadian nationals.

Access was almost careless. Direct connections to the cluster returned an authentication error, but a second cloud route to the same data accepted factory-default logins. Combining the two weaknesses gave full access. Intelligence platform FOFA had recorded the host as early as October 2022 and labelled it a database service in July 2023, though nobody can say when passenger data became reachable through the weaker path. Vietnam remains a booming destination for Indian travellers, with record August arrivals including a surge from India, which widens the pool of potentially affected flyers.

FactDetail
Records exposed220,783,700 trip and crew entries (not unique people)
Data volumeAbout 107GB across 29 indices
Time spanJanuary 2017 to April 2026
Identity fieldsNames, birth dates, sex, nationality, passport numbers, expiry, issuing country
Journey fieldsFlight numbers, airlines, airports, transit points, seats, baggage refs, timings
Hosting traceIP space of Viettel, Hanoi; operator unconfirmed
DiscovererKinryu Labs, found June 3 during ransomware research
SecuredJune 8, with Singapore Airlines coordinating

Who found the database and what happened next?

Credit goes to Kinryu Labs, which stumbled on the cluster on June 3 while hunting exposed databases for ransomware research and verified the contents by matching records against its own researchers' documented trips to Vietnam. The same day it notified Vietnamese authorities, affected airlines and national computer emergency response teams. By June 8 the grouping was locked down.

Singapore Airlines helped coordinate the response. Its security team said in a June 8 email that it had engaged the relevant parties and taken steps to contain the issue; Changi Airport Group examined the incident and declined further comment. Importantly, researchers found no evidence that any listed airline operated the system or was itself breached, and there were no ransom notes or signs the data was altered. Without server-side access logs, though, exfiltration cannot be ruled out. If you are applying for travel documents, our Vietnam e-visa requirements guide explains which details the official channels legitimately ask for.

What should travellers who flew via Vietnam do?

First, treat the combination of passport number, birth date and travel history as live. That trio powers convincing phishing: emails that cite your real past flights to Vietnam and ask you to re-verify documents. Do not click document links in unsolicited messages from airlines or immigration authorities; go to official sites directly.

Second, consider refreshing the travel-security basics we covered in our hotel Wi-Fi security warning: unique passwords on airline and booking accounts, two-factor authentication where offered, and a freeze or alert with your credit bureau if your country offers it. Third, watch for targeted fraud referencing seat numbers or baggage tags from old trips, details ordinary scammers would not know. Whether Vietnam's unidentified system operator faces regulatory action is still unknown, and remains the accountability question to track.

Frequently asked questions

Was my data in the Vietnam APIS leak?

Possibly, if you flew to, from or through Vietnam between January 2017 and April 2026 on an airline feeding the system. With no access logs, nobody can confirm whose records were viewed, so affected-window travellers should assume inclusion and harden their accounts.

What data was exposed?

Names, birth dates, sex, nationalities, passport numbers with expiry and issuing country, plus flight numbers, airlines, origin, destination and transit airports, seats, baggage references and scheduled and actual timings.

Which airlines were affected?

Carriers across Asia-Pacific, Europe and the Middle East appear in the data. Researchers stress there is no sign the airlines operated the database or were breached themselves; Singapore Airlines assisted in coordinating the containment.

Is the database still exposed?

No. It was reported on June 3 and secured by June 8. The disclosure became public through security-press reporting on September 8, which is why travellers are learning of it now.

Sources

Share this article

Travel Market News Desk

Travel Industry News & Analysis

The Travel Market News Desk is the editorial team behind Travel Market News. We cover the business of travel — aviation, hospitality, tourism, destinations and the technology reshaping how the world moves — turning a fast-moving market into clear, useful intelligence for the professionals who build it. Our reporting is independent, fact-checked and global in outlook.