A Vietnam APIS data leak has left more than 220 million passenger and crew records accessible online, including passport numbers, flight details, and personal travel histories spanning nearly a decade. The database, which appears linked to a Vietnamese organisation, was reachable through a chain of security misconfigurations rather than a single, obvious vulnerability.

Advance Passenger Information Systems (APIS, for those who haven’t had to fill out an embarkation card recently) are the infrastructure governments and airlines use to collect identity, passport, and itinerary data before travellers arrive at or depart from a country. That makes the contents of an exposed APIS database considerably more sensitive than, say, a leaked marketing list.

What the Vietnam APIS data leak contained

Kinryū Labs discovered the exposed Elasticsearch cluster on 3 June while surveying databases as part of research into ransomware activity. The cluster, named ‘pax-info’, held 29 indices and approximately 107 GB of data. Its two principal indices contained 210,318,069 passenger records and 10,465,631 crew records, combining for a total of 220,783,700 entries. Kinryū Labs told BleepingComputer that the cluster was hosted in Viettel-assigned IP space in Hanoi. Which Vietnamese organisation actually operated the system could not be confirmed.

The records cover travel between January 2017 and April 2026, just over nine years of data. Exposed fields included passengers’ and crew members’ names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data stretched further still: flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times.

Sample records reviewed by BleepingComputer included travellers of Korean, Chinese, Canadian, and New Zealand nationality, among others. The database covered numerous international airlines across Asia-Pacific, Europe, and the Middle East, meaning the exposed records could, in principle, relate to people from virtually anywhere who visited or transited through Vietnam during that period. Kinryū Labs verified the data’s legitimacy by matching records against its own researchers’ travel to Vietnam. One caveat worth noting: the figures represent travel records, not unique individuals. Frequent flyers will appear multiple times.

A chained misconfiguration, not a forced entry

The access path is the part that should make security teams uncomfortable. From the open internet, the endpoint returned an HTTP 401 “Unauthorized” response, so a casual scan would log it as protected and move on. However, Kinryū Labs found a cloud-based path that allowed researchers to reach the cluster, which then accepted default credentials. Two misconfigurations, chained together, undid whatever the 401 response was supposed to guarantee.

Internet intelligence platform FOFA first recorded the host and port in October 2022 and identified the service as a database in July 2023. Kinryū Labs could not determine when the passenger data first became retrievable through the second access path, so the actual duration of the exposure remains unknown, even though the records themselves stretch back to 2017.

The researchers reported the issue to Vietnamese authorities, airlines represented in the database, and national computer emergency response teams beginning 3 June. Access to the database was remediated on 8 June. An authenticated email reviewed by BleepingComputer shows that Singapore Airlines‘ security team helped coordinate the response, informing Kinryū Labs on 8 June that it had ‘engaged the relevant parties’ and ‘taken steps to contain the issue.’ Singapore Airlines declined to provide further comment. Changi Airport Group, which manages and operates Singapore’s Changi Airport, said it had investigated the matter but also declined to comment. Vietnamese authorities had not responded to BleepingComputer prior to publication.

There is no indication that any of the airlines whose records appeared in the database operated the exposed system or that their own networks were compromised.

Whether the data was copied remains an open question

Kinryū Labs found no ransom notes or unfamiliar indices on the cluster, and could not identify the dataset being offered for sale online. Without access to server logs, however, the researchers cannot conclusively say whether anyone exfiltrated the data before it was secured. The question of whether 220 million records were quietly copied, ransomed, or simply left untouched by everyone except security researchers is, for now, unanswered. Kinryū Labs expects to publish additional technical findings on its blog later this week.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version