Massive Data Breach Exposes 220 Million Passenger Records in Vietnam

Massive Data Breach Exposes 220 Million Passenger Records in Vietnam

First seen 8 Sep 2026, 12:03 UTC Securityaffairs.Cowww.bleepingcomputer.comkinryu.sh 66.5

Article Content

Browse articles
ThreatCluster

A significant data breach involving an Advance Passenger Information System (APIS) database has exposed over 220 million passenger and crew records linked to Vietnam. Discovered by Kinryū Labs, the Elasticsearch cluster, named 'pax-info', contained sensitive information including passport numbers, flight details, and personal identities from January 2017 to April 2026. The database was accessible online due to a series of security misconfigurations, allowing unauthorized access through default credentials. The records could potentially affect travelers of various nationalities who flew to, from, or through Vietnam during the nine-year period. Kinryū Labs confirmed the legitimacy of the data by matching it with their own travel records. The database was hosted on IP space assigned to Viettel in Hanoi, but the specific organization operating it remains unidentified. This incident highlights ongoing vulnerabilities in database security and the risks posed by misconfigurations.

Key Points: • Over 220 million passenger records exposed due to security misconfigurations. • Sensitive data includes passport numbers, flight details, and personal identities. • Database linked to a Vietnamese organization but remains unconfirmed.

Ask AI about this cluster

Timeline

2022-10-01
FOFA first recorded the host
The internet intelligence platform FOFA identified the host and port for the database in October 2022.
BleepingComputer
2023-07-01
Service identified as database
FOFA identified the service as a database in July 2023, indicating ongoing exposure.
BleepingComputer
2026-04-22
CVE-2026-31431 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-03
Database discovered by Kinryū Labs
Kinryū Labs discovered the exposed Elasticsearch cluster during research into ransomware activity.
BleepingComputer
2026-09-08
Breach reported
The breach was reported on September 8, 2026, detailing the extent of the data exposure.
BleepingComputer