Misconfigured Database Exposes 220 Million Traveler Records Linked to Vietnam
Security researchers at Kinry Labs discover an exposed Elasticsearch cluster containing more than 220 million passenger and crew records from an Advance Passenger Information System (APIS) that appears linked to a Vietnamese organization. The database, named 'pax-info', holds roughly 107 GB of data across 29 indices, including 210 million passenger records and 10 million crew records. The cluster resides in Viettel-assigned IP space in Hanoi, though the specific operator remains unconfirmed.
The exposed records span January 2017 to April 2026 and include travelers' full names, dates of birth, nationalities, passport numbers, document expiration dates, and issuing countries. Detailed flight information is also present, covering flight numbers, airlines, departure and transit airports, seat assignments, baggage references, and scheduled and actual flight times. Sample records reviewed by BleepingComputer include travelers of Korean, Chinese, Canadian, and New Zealand nationality, and the data involves numerous international airlines across Asia-Pacific, Europe, and the Middle East.
Because the database covers nine years of travel to, from, and through Vietnam, people from virtually anywhere in the world could be affected. Kinry Labs finds the cluster on June 3 while researching ransomware activity and verifies the legitimacy of the data by matching records against its own researchers' travel information. The exposure underscores the significant privacy and security risks that arise when sensitive government-linked travel databases suffer security misconfigurations.