A massive security failure in a Vietnam-linked Advance Passenger Information System (APIS) has exposed the sensitive data of 220 million travelers and crew members.
- Over 220 million passenger and crew records were exposed online.
- Sensitive data includes passport numbers, DOB, and flight details.
- The breach spans records from January 2017 to April 2026.
- Access was gained through cloud misconfigurations and default credentials.
In a massive cybersecurity breach, an Advance Passenger Information System (APIS) database containing over 220 million records has been found exposed online. The database, which appears to be linked to an organization in Vietnam, contained highly sensitive information belonging to passengers and airline crew members worldwide.
The breach was discovered by Kinryū Labs, who identified an Elasticsearch cluster named 'pax-info' during their research into ransomware activity. The cluster held approximately 107 GB of data, comprising over 210 million passenger records and more than 10 million crew records. The exposed data covers a massive nine-year window, from January 2017 to April 2026.
What Information Was Exposed?
The leaked data is extensive and highly sensitive. It includes full names, dates of birth, sex, nationalities, and passport or travel document numbers, along with expiration dates and issuing countries. Beyond identity details, the leak included critical travel logistics such as flight numbers, airlines, departure and destination airports, seat assignments, and baggage references.
The scale of this exposure highlights a critical vulnerability in how international travel data is managed across cloud infrastructures.
Why This Matters
BozokMedia analysis shows that this incident is a textbook example of how 'chained misconfigurations' can lead to catastrophic data exposure. While the database initially returned an 'Unauthorized' response to direct internet queries, a secondary cloud-based path allowed researchers to bypass security using default credentials. This underscores the danger of neglecting basic security hygiene in cloud-hosted databases.
Historical Background
APIS is a standardized global mechanism used by border agencies to collect traveler information before they arrive at a destination. This data is vital for national security and preventing illegal border crossings. However, as travel becomes increasingly digitized, the centralization of such massive datasets creates a high-value target for cybercriminals and state-sponsored actors.
While researchers have confirmed the legitimacy of the data by matching it against their own travel records, it remains unclear if malicious actors have already exploited the leak. Although the vulnerability was remediated on June 8, 2026, the question of whether the data was downloaded or sold remains unanswered due to a lack of server logs.
Frequently Asked Questions
1. Does this mean my airline account was hacked?
Not necessarily. The breach involved an APIS database used for passenger info, not necessarily the internal networks of the airlines themselves.
2. Who was affected by this leak?
Anyone who traveled to, from, or through Vietnam between 2017 and 2026 could potentially be included in the exposed records.