Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 13, 2026 · 6 min read

220M Traveler Records Exposed in APIS Leak

An Elasticsearch cluster named pax-info held nine years of border control manifests for flights to, from and through Vietnam. Researchers closed it in five days. Nobody has said who owned it.

Most leaked databases are marketing lists. This one was a border control archive. Roughly 107 GB of Advance Passenger Information piled up across 29 indices between January 2017 and April 2026: names, dates of birth, nationalities, passport numbers, expiry dates, seat assignments, takeoff times. It sat on the open internet, and no organization has claimed it.

Key Takeaways

  • Kinryū Labs found an exposed Elasticsearch cluster on 3 June 2026 holding 210,318,069 passenger records and 10,465,631 crew records, or 220,783,700 entries in total, as first reported by BleepingComputer.
  • The exposed fields are Advance Passenger Information: passport numbers, document expiry dates, issuing countries, dates of birth, nationalities, flight numbers, airports, seat assignments and baggage references.
  • The records cover January 2017 through April 2026 and describe travelers who flew to, from or through Vietnam.
  • The server sat in IP space assigned to Viettel in Hanoi, but no organization has been confirmed as the operator of the database.
  • The cluster was secured on 8 June 2026, five days after Kinryū Labs notified Vietnamese authorities, national CERTs and affected airlines, with Singapore Airlines helping coordinate.

What Is APIS Data and Why Do Airlines Collect It?

Advance Passenger Information is the passport level data an airline must send to a destination country's border authority before the aircraft departs. Not an optional marketing field. A condition of being allowed to fly.

US Customs and Border Protection requires operators on international flights to transmit manifests electronically before departure. The obligation traces to ICAO Annex 9, and the permitted fields are fixed by joint WCO, IATA and ICAO guidelines down to the field.

That standardization is what makes the dataset dangerous. Every record follows one schema, so 220 million entries are machine readable the moment they are downloaded. A clean, queryable index of who went where.

How Was the Database Exposed?

Two separate misconfigurations, chained. One endpoint faced the internet directly and returned an HTTP 401, which looks like a locked door. A second cloud based path into the same cluster accepted default credentials, the exact failure Elastic's minimal security setup exists to prevent.

The 401 is the part worth dwelling on. Any scan or compliance check that probed the public endpoint came back clean. The front door was locked. The side entrance still had the factory key in it.

Kinryū Labs did not stumble on it either. The researchers were surveying exposed databases as part of ransomware research, which is the same sweep extortion crews run at the same scale. The only variable is who looked first.

Airport departures hall with passengers passing a border control desk, a passport and boarding pass resting on the counter, indigo and blue lighting

Who Actually Ran the Server?

Nobody has said, and that is the genuinely unresolved part of the story. The cluster sat in IP space assigned to Viettel in Hanoi. Viettel is Vietnam's largest telecom operator and also sells cloud hosting, so the address block says where the machine sat, not who filled it. A border agency, an airport operator, a ground handler and a data aggregator are all plausible. Anything beyond "hosted in Viettel assigned space" is unverified.

An unowned breach is a broken breach. With no confirmed controller, nobody is obliged to notify 220 million travelers and nobody can say whether the data was copied before 8 June. The gap rhymes with the UK Criminal Records Office intrusions that went unnoticed three separate times: the failure is not only the exposure, it is that nobody was watching the thing they were accountable for.

Why a Passport Number Is Worse Than a Leaked Password

A password takes thirty seconds to change. A passport number changes only when you apply for, pay for and wait on a replacement document, and no country issues one because your number turned up in a database.

Scale is the other half. INTERPOL's Stolen and Lost Travel Documents database, which border officers in 190 countries query before waving anyone through, holds around 138 million entries. The Vietnam cluster held more records than that. They repeat travelers across trips, so distinct people number fewer and nobody has published how many, but the archive is the same order of magnitude as the global machinery built to catch document fraud.

An APIS record beats a scanned document because of the itinerary bolted to it. A passport number alone is a string. That number beside a date of birth, a nationality, seat 34K on a named flight and a baggage reference is enough to sound like the airline on the phone. The same pattern drove the 153 million driver's license scans stolen from IDScan: government issued identifiers turn dangerous the moment they sit next to context. The 10,465,631 crew records add a second problem, showing which cabin and flight deck staff work which routes on what schedule.

What It Means for Compliance and Border Policy

The timing is awkward for Vietnam. Its Personal Data Protection Law, Law 91/2025/QH15, took effect on 1 January 2026 and requires notification of qualifying breaches within 72 hours, with penalties scaling to a share of prior year revenue. Most of the exposed records predate the law. The exposure itself, in June 2026, does not.

Europe is moving the other way on architecture. Regulation (EU) 2025/12, which repeals the 2004 carrier directive, pushes API data through one eu-LISA router that encrypts end to end and deletes immediately after routing. No long lived store. No nine year archive. The Vietnam cluster is the argument for that design, made in the negative.

Most coverage has fixed on the headline number. The precedent that matters more: when a state mandates collection but the resulting repository has no publicly accountable owner, the regulatory machinery has nothing to grip. Fines need a defendant. Notification needs a notifier.

What Can Travelers Do Now?

Very little about the record itself. You never chose to hand over the passport number and cannot ask for it back. What you can change is how you answer anyone who already has it.

  • Assume the number is public if you flew through Vietnam between 2017 and 2026. Stop treating passport digits as a shared secret, and never confirm them to an inbound call, text or email however much flight detail the sender quotes.
  • Expect itinerary aware approaches. A message citing your real flight number, route and seat is not proof it came from the airline. Close it and call the carrier on the number listed on its own site.
  • Do not report a leaked number as a lost or stolen passport. Your document is not lost. A false report lands it in INTERPOL's SLTD and can get you turned away at a border. Report only if the physical passport is actually gone.
  • Let renewal do the work. A new passport carries a new number, so renewing on schedule quietly retires the exposed identifier.
  • Lock down airline loyalty accounts. Turn on two factor authentication and review recent activity, since frequent flyer programs are a standard first target when travel data circulates, the same follow on risk that shadowed the Manchester Airports breach that hit 8.7 million customers.

What We Still Do Not Know

Three things stay open. Nobody has confirmed which organization operated the cluster. Nobody has established whether the records were downloaded, sold or ransomed during the window they were reachable. And nobody has published how long the cluster sat exposed before Kinryū Labs found it on 3 June.

That unknown decides how bad this was. A cluster open a week is an incident. A cluster open a year, when scanning the whole IPv4 space takes minutes, is closer to a guarantee someone else got there first. The five day fix was quick. The question is what the clock read before it started.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.