www.bleepingcomputer.com
Massive Data Breach Exposes 220 Million Passenger Records in Vietnam
Article Content
A significant data breach involving an Advance Passenger Information System (APIS) database has exposed over 220 million passenger and crew records linked to Vietnam. Discovered by Kinryū Labs, the Elasticsearch cluster, named 'pax-info', contained sensitive information including passport numbers, flight details, and personal identities from January 2017 to April 2026. The database was accessible online due to a series of security misconfigurations, allowing unauthorized access through default credentials. The records could potentially affect travelers of various nationalities who flew to, from, or through Vietnam during the nine-year period. Kinryū Labs confirmed the legitimacy of the data by matching it with their own travel records. The database was hosted on IP space assigned to Viettel in Hanoi, but the specific organization operating it remains unidentified. This incident highlights ongoing vulnerabilities in database security and the risks posed by misconfigurations.
Key Points: • Over 220 million passenger records exposed due to security misconfigurations. • Sensitive data includes passport numbers, flight details, and personal identities. • Database linked to a Vietnamese organization but remains unconfirmed.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.