-
Researchers found an unsecured database holding over 220 million passenger and crew records, including passport numbers and flight details.
-
The exposed records cover nine years of travel data, spanning January 2017 to April 2026, and affect travelers of many nationalities.
-
Security researchers reported the issue on June 3, and access to the database was shut down by June 8.
A massive passenger database sat open online, exposing the travel records of over 220 million people. Researchers discovered the system carries names, passport numbers, and flight details belonging to travelers who flew to, from, or through Vietnam over nine years. The database appears linked to a Vietnamese organization, though the exact operator remains unconfirmed.
Advance Passenger Information Systems (APIS) collect identity and travel data from airlines before passengers arrive at or leave a country. Governments and aviation authorities use them worldwide to screen travelers in advance.
Nine Years of Passenger and Crew Data Left Open
Cybersecurity research group Kinryū Labs found the exposed database on June 3 while scanning for unsecured systems as part of ongoing research into ransomware activity.
The database, named “pax-info,” ran on an Elasticsearch cluster. It held 29 separate data groups and roughly 107 gigabytes of information. Two main sections inside it stored 210,318,069 passenger records and 10,465,631 crew records. That brings the combined total to 220,783,700 entries.
According to Kinryū Labs, the cluster ran on servers assigned to Viettel, a Vietnamese telecoms provider, in Hanoi. BleepingComputer could not confirm which specific Vietnamese organization operated the system.
The exposed records included full names, dates of birth, gender, nationalities, and passport or travel document numbers. Document expiration dates and issuing countries were also present. On top of that, the database stored flight numbers, airlines, departure and arrival airports, transit stops, seat numbers, baggage references, and flight times.
Sample records reviewed by BleepingComputer included travelers from South Korea, China, Canada, and New Zealand, among other nationalities. The data covered airlines across Asia-Pacific, Europe, and the Middle East. In practice, this means the leak could affect travelers from almost any country who passed through Vietnam between January 2017 and April 2026.
Kinryū Labs confirmed the data was real. The team matched records in the database against their own researchers’ personal travel history to Vietnam. One important note: the figures reflect travel records, not unique people. A passenger or crew member who flew multiple times during that period may appear in the database more than once.
How Researchers Got in
Kinryū Labs reached the database by following a chain of two separate security mistakes. From the open internet, the database returned an “Unauthorized” error, blocking direct access. However, a separate cloud-based path allowed researchers to reach the same system. Once there, the cluster accepted default login credentials, meaning no special hacking tools were needed.
Internet intelligence platform FOFA first recorded the server in October 2022 and flagged it as a database in July 2023. Kinryū Labs could not determine exactly when the passenger data became reachable through the second access path. So while the records themselves cover more than nine years, the actual length of the exposure is unknown.
Kinryū Labs began reporting the issue to Vietnamese authorities, airlines in the database, and national computer emergency teams on June 3. Access to the database was closed on June 8.
An authenticated email reviewed by BleepingComputer shows Singapore Airlines played a key role in the response. The airline’s security team told Kinryū Labs on June 8 that it had reached the right parties and taken steps to contain the situation. Singapore Airlines did not offer further comment to BleepingComputer.
Changi Airport Group, which runs Singapore’s Changi Airport, told BleepingComputer it looked into the matter but chose not to comment. Vietnamese authorities received contact from BleepingComputer well before publication but did not respond.
What Happened to the Data
It remains unclear whether anyone downloaded, sold, or held the data for ransom before researchers secured it. Kinryū Labs found no ransom notes and no unfamiliar entries inside the cluster. The team also could not find the dataset being sold anywhere online.
However, without access to the server’s activity logs, the researchers cannot say for certain that no one copied the data before it was locked down.
A separate dark web listing claims to offer an alleged database from Clark International Airport in the Philippines, containing passport numbers, birth dates, phone numbers, gender information, and physical addresses.
Several major airlines had passenger records appear in the database, according to findings shared with BleepingComputer. There is no sign that the airlines operated the exposed system. There is also no evidence that their own networks were affected in any way.
The findings highlight how a simple chain of misconfigurations can expose enormous amounts of sensitive travel data. Passport numbers, flight histories, and personal details, in the wrong hands, can fuel identity theft, fraud, or targeted scams against travelers.
Kinryū Labs says it plans to publish a more detailed technical breakdown of its findings on its blog in the coming days.