discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

220 Million Traveler Records Exposed in Vietnam-Linked API Leak

220 million traveler records exposed in a Vietnam-linked API leak, spanning 9 years of data from January 2017 to April 2026.

By Ax Sharma·Sep 8·bleepingcomputer.com·2 min read

Intelligence analysis by Qwen 2.5 (3B)

220 Million Traveler Records Exposed in Vietnam-Linked API Leak
Image: bleepingcomputer.com

Researchers discovered an exposed Elasticsearch cluster containing 220 million traveler records, including passport numbers and flight details, linked to a Vietnamese organization.

Why it matters

This breach exposes sensitive personal and travel information of millions of people, raising concerns about data security and privacy in international travel.

A big computer system with lots of personal information about travelers, like names, birth dates, and flight details, was found to be open to the internet. This information could belong to people from many different countries who flew to or through Vietnam.

Analysis

{"heading_1":"Data Exposure Details","paragraph_1":"Kinryū Labs discovered an Elasticsearch cluster named 'pax-info' containing 29 indices and approximately 107 GB of data, with passenger and crew records spanning from January 2017 to April 2026.","paragraph_2":"The cluster was hosted in Viettel-assigned IP space in Hanoi, Vietnam. The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries.","paragraph_3":"The database contained associated travel data such as flight numbers, dates, airlines, departure, destination, and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times.","paragraph_4":"The exposed records covered numerous international airlines across Asia-Pacific, Europe, and the Middle East, potentially relating to travelers from virtually anywhere who visited or transited through Vietnam over the nine-year period.","paragraph_5":"Kinryū Labs verified the legitimacy of the records by matching them against its own travel to Vietnam. The database was accessible through two misconfigurations, allowing researchers to reach the cluster and access the data.","paragraph_6":"The actual length of the exposure is unknown, as the records span more than nine years. Kinryū Labs reported the issue to Vietnamese authorities, airlines represented in the database, and national computer emergency response teams on June 3, and remediation was completed on June 8.","paragraph_7":"Singapore Airlines' security team helped coordinate the response, informing Kinryū Labs on June 8 that it had engaged the relevant parties and taken steps to contain the issue. Changi Airport Group declined to comment on the matter."}

Key points

  • 220 million traveler records exposed in a Vietnam-linked API leak
  • Data spans 9 years from January 2017 to April 2026
  • Includes passport numbers, flight details, and associated travel data
  • Accessed through two misconfigurations in the Elasticsearch cluster
  • Exposes information of travelers from many countries who visited or transited through Vietnam
The Upside

The exposed data will likely be secured and the system will be fixed to prevent similar breaches in the future.

The Downside

The breach could have exposed sensitive information that could be used for identity theft or other malicious activities.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritydata-breachtravelapi-leakvietnam

Author

Ax Sharma

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 8, 2026

Source

bleepingcomputer.com

Share

Topics

securitydata-breachtravelapi-leakvietnam

Related

More from this desk

Sep 7·bleepingcomputer.com

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento zero-day vulnerability exploited to deploy Linux backdoor. Adobe Enterprise Support working on fix.

Sep 7·thehackernews.com

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters disclose a data theft and extortion threat targeting Microsoft 365 and SaaS users through fake IT calls and proxy sign-ins.

Sep 7·bleepingcomputer.com

BigBear Microsoft 365 phishing service bypasses MFA at 258 organizations

Phishing-as-a-service framework BigBear 2.0 bypassed MFA at 258 organizations, stealing over 5,000 Microsoft 365 credentials.

Sep 7·thehackernews.com

Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

This week, attackers used a QR code workaround to bypass email image blocking, and a trusted software source delivered code that stole credentials. MikroTik RouterOS flaws were exploited, and Magento and Adobe Commerce were compromised with an unpatched zero-day.