220 million traveler records exposed in Vietnam-linked APIS leak
An exposed Advance Passenger Information System (APIS) database linked to a Vietnamese organization contained over 220 million passenger and crew records spanning from 2017 to 2026. The data included sensitive personal information such as names, passport numbers, dates of birth, nationalities, and detailed flight information. Researchers accessed the database through a cloud-based path using default credentials, exploiting chained misconfigurations. The exposure was reported and remediated in June 2026. It is unclear if the data was accessed maliciously or exfiltrated prior to remediation.
AI Analysis
Technical Summary
A large Elasticsearch cluster named 'pax-info' containing approximately 220 million passenger and crew records was discovered exposed online. The database held detailed APIS data including identity and travel details for individuals who traveled to, from, or through Vietnam over a nine-year period. Access was gained by chaining two misconfigurations: an HTTP 401 response blocked direct access, but a cloud-based path allowed entry using default credentials. The cluster was hosted in Viettel-assigned IP space in Hanoi. The exposure was reported to Vietnamese authorities and airlines starting June 3, 2026, and access was remediated by June 8, 2026. There is no evidence of ransom notes or data being sold, but the extent of potential data misuse is unknown due to lack of server logs.
Potential Impact
The exposure potentially compromises the personal and travel information of over 220 million passenger and crew records, including sensitive data such as passport numbers and flight details. This could lead to privacy violations, identity theft, and targeted attacks against affected individuals. The data covers multiple nationalities and international airlines, indicating a broad impact. However, there is no confirmed evidence of malicious exploitation or data exfiltration prior to remediation.
Mitigation Recommendations
The issue was reported to relevant Vietnamese authorities, airlines, and national computer emergency response teams. Access to the database was remediated on June 8, 2026, by addressing the misconfigurations and removing default credentials. No further action is indicated by the reporting researchers. Organizations should verify that no unauthorized access occurred and review access controls to prevent similar exposures.
220 million traveler records exposed in Vietnam-linked APIS leak
Description
An exposed Advance Passenger Information System (APIS) database linked to a Vietnamese organization contained over 220 million passenger and crew records spanning from 2017 to 2026. The data included sensitive personal information such as names, passport numbers, dates of birth, nationalities, and detailed flight information. Researchers accessed the database through a cloud-based path using default credentials, exploiting chained misconfigurations. The exposure was reported and remediated in June 2026. It is unclear if the data was accessed maliciously or exfiltrated prior to remediation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A large Elasticsearch cluster named 'pax-info' containing approximately 220 million passenger and crew records was discovered exposed online. The database held detailed APIS data including identity and travel details for individuals who traveled to, from, or through Vietnam over a nine-year period. Access was gained by chaining two misconfigurations: an HTTP 401 response blocked direct access, but a cloud-based path allowed entry using default credentials. The cluster was hosted in Viettel-assigned IP space in Hanoi. The exposure was reported to Vietnamese authorities and airlines starting June 3, 2026, and access was remediated by June 8, 2026. There is no evidence of ransom notes or data being sold, but the extent of potential data misuse is unknown due to lack of server logs.
Potential Impact
The exposure potentially compromises the personal and travel information of over 220 million passenger and crew records, including sensitive data such as passport numbers and flight details. This could lead to privacy violations, identity theft, and targeted attacks against affected individuals. The data covers multiple nationalities and international airlines, indicating a broad impact. However, there is no confirmed evidence of malicious exploitation or data exfiltration prior to remediation.
Defensive Guidance
The issue was reported to relevant Vietnamese authorities, airlines, and national computer emergency response teams. Access to the database was remediated on June 8, 2026, by addressing the misconfigurations and removing default credentials. No further action is indicated by the reporting researchers. Organizations should verify that no unauthorized access occurred and review access controls to prevent similar exposures.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a9fbb2bacd9273b4943f188
Added to database: 09/08/2026, 07:37:15 UTC
Last enriched: 09/08/2026, 07:37:25 UTC
Last updated: 09/08/2026, 13:01:39 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.