Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-09 · updated: 2026-09-09 · tags: [incident, data-exposure, travel, aviation, misconfiguration, apis] · confidence: medium · affected_sectors: [transport, government] · au_impact: true

220 Million Traveler Records Exposed in Vietnam-Linked APIS Leak

Researcher Kinryū Labs discovered on 3 June an Elasticsearch cluster named "pax-info" hosted in Viettel-assigned IP space in Hanoi holding 210,318,069 passenger and 10,465,631 crew records (~220 million combined, ~107 GB) spanning January 2017 to April 2026, including names, dates of birth, nationalities, passport numbers, issuing countries, flight numbers, seat assignments and timings.

Attribute Detail
Scope ~220M records (passage + crew), ~107 GB
Location Hanoi; Viettel-assigned IP space
Vector Chain of two misconfigurations (open endpoint returned 401, but a cloud-based path accepted default credentials)
Coverage Airlines across APAC, Europe, Middle East; sample records incl. Korean, Chinese, Canadian, NZ travellers
Remediation Secured by 8 June
Verification Legitimacy verified against researchers' own Vietnam travel; download/ransom not confirmed
Source BleepingComputer — Tier 2/4

Kinryū Labs verified legitimacy by matching records against its own Vietnam travel. The database was remediated by 8 June, but it could not confirm whether anyone downloaded or ransomed it before it was secured, and the findings identify several major airlines whose passenger records appeared without any indication their own networks were breached. NZ citizens' passport and flight data sat in this nine-year, publicly reachable travel dataset — a reminder of the OAIC/Privacy Act notification relevance for AU/NZ travellers.

Source