220 Million Traveler Records Exposed in Vietnam-Linked API Leak
220 million traveler records exposed in a Vietnam-linked API leak, spanning 9 years of data from January 2017 to April 2026.
Intelligence analysis by Qwen 2.5 (3B)

Researchers discovered an exposed Elasticsearch cluster containing 220 million traveler records, including passport numbers and flight details, linked to a Vietnamese organization.
A big computer system with lots of personal information about travelers, like names, birth dates, and flight details, was found to be open to the internet. This information could belong to people from many different countries who flew to or through Vietnam.
Analysis
{"heading_1":"Data Exposure Details","paragraph_1":"Kinryū Labs discovered an Elasticsearch cluster named 'pax-info' containing 29 indices and approximately 107 GB of data, with passenger and crew records spanning from January 2017 to April 2026.","paragraph_2":"The cluster was hosted in Viettel-assigned IP space in Hanoi, Vietnam. The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries.","paragraph_3":"The database contained associated travel data such as flight numbers, dates, airlines, departure, destination, and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times.","paragraph_4":"The exposed records covered numerous international airlines across Asia-Pacific, Europe, and the Middle East, potentially relating to travelers from virtually anywhere who visited or transited through Vietnam over the nine-year period.","paragraph_5":"Kinryū Labs verified the legitimacy of the records by matching them against its own travel to Vietnam. The database was accessible through two misconfigurations, allowing researchers to reach the cluster and access the data.","paragraph_6":"The actual length of the exposure is unknown, as the records span more than nine years. Kinryū Labs reported the issue to Vietnamese authorities, airlines represented in the database, and national computer emergency response teams on June 3, and remediation was completed on June 8.","paragraph_7":"Singapore Airlines' security team helped coordinate the response, informing Kinryū Labs on June 8 that it had engaged the relevant parties and taken steps to contain the issue. Changi Airport Group declined to comment on the matter."}
Key points
- 220 million traveler records exposed in a Vietnam-linked API leak
- Data spans 9 years from January 2017 to April 2026
- Includes passport numbers, flight details, and associated travel data
- Accessed through two misconfigurations in the Elasticsearch cluster
- Exposes information of travelers from many countries who visited or transited through Vietnam
The exposed data will likely be secured and the system will be fixed to prevent similar breaches in the future.
The breach could have exposed sensitive information that could be used for identity theft or other malicious activities.



