KINRY ū Labs disclosed a publicly exposed Advance Passenger Information System (APIS) database linked to Vietnam that contained about 220.8 million passenger and crew records dating from January 2017 to April 2026. The dataset includes sensitive details such as passport numbers, identities, and flight information, affecting travellers who flew to, from or via Vietnam over roughly nine years. The Elasticsearch cluster, named “pax-info,” held about 107 GB of data across 29 indices.
Researchers linked the server to IP space assigned to Viettel in Hanoi, though they could not confirm which Vietnamese organisation operated the system. The exposure is described as travel records rather than unique individuals, so frequent travellers may appear multiple times.
Kinryū Labs verified the data’s legitimacy by matching records against their own travel to Vietnam, and noted two security misconfigurations allowed access: direct internet access returned a 401 error, while a second cloud-based path exposed the cluster and accepted default credentials. FOFA first detected the host in 2022 and identified it as a database in 2023, but the exact time of data exposure remains unknown.
The researchers notified Vietnamese authorities, affected airlines and national CERTs on 3 June, and the database was secured by 8 June, with Singapore Airlines assisting the response. While investigators found no evidence that airlines operated the system or suffered a breach, nor signs of ransom notes or data tampering, the absence of server logs means they cannot determine whether data was copied before securing the server.