An Advance Passenger Information System (APIS) database containing more than 220 million passenger and crew records was exposed online because of multiple security misconfigurations. The database included sensitive information such as passport numbers, personal details, and flight data. Researchers who discovered the exposure said the system appears to be linked to an organization in Vietnam.
Airlines and government agencies worldwide use Advance Passenger Information Systems to collect identity, passport, and travel details before passengers and crew members arrive in or depart from a country.
The exposed records span from January 2017 through April 2026 and may include travelers of numerous nationalities who flew to, from, or through Vietnam during that period.
Exposed APIS database contained nine years of passenger and crew data
Kinryu Labs discovered the Elasticsearch cluster on June 3 while investigating exposed databases during research into ransomware activity.
The cluster, named “pax-info,” contained 29 indexes and approximately 107 GB of data. Its two primary indexes contained 210,318,069 passenger records and 10,465,631 crew records, totaling 220,783,700 entries.
According to Kinryu Labs, the Elasticsearch cluster was hosted within IP address space allocated by Viettel in Hanoi. BleepingComputer could not independently confirm which Vietnamese organization operated the system.
The exposed information included passenger and crew names, dates of birth, gender, nationality, passport or travel document numbers, document expiration dates, and issuing countries.
The associated travel information included flight numbers and dates, airlines, departure airports, destinations, transit airports, seat assignments, baggage references, scheduled flight times, estimated flight times, and actual flight times. This type of information is commonly maintained by APIS platforms and related airline systems.
Sample records reviewed by BleepingComputer included travelers from South Korea, China, Canada, and New Zealand.

(Kinryu Institute)
Although the researchers could not provide a complete breakdown by nationality, the database contained records associated with major international airlines operating across the Asia-Pacific region, Europe, and the Middle East. The exposure could therefore affect people from many countries who traveled to or through Vietnam during the nine-year period.
Kinryu Institute verified the authenticity of the data by comparing database records with the researchers’ own travel information from trips to Vietnam.
The record totals represent individual travel records rather than unique people. Passengers and crew members who traveled multiple times may therefore appear in the database more than once.
Multiple security misconfigurations exposed the database
Kinryu Labs told BleepingComputer that two separate misconfigurations combined to make the APIS database accessible.
When accessed directly from the internet, the endpoint returned an HTTP 401 “Unauthorized” response, blocking direct access to the database. However, the cloud-based access path enabled the researchers to reach the Elasticsearch cluster, which accepted the default credentials.
Internet intelligence platform FOFA first recorded the host and port in October 2022 and identified the service as a database in July 2023. Kinryu Labs could not determine when the passenger data first became accessible through the secondary access path.
The exact duration of the exposure is therefore unknown, even though the records themselves cover more than nine years of travel activity.
Kinryu Labs said it began notifying Vietnamese authorities, airlines represented in the database, and the National Computer Emergency Response Team on June 3. Researchers said access to the database was restored on June 8.
A verified email reviewed by BleepingComputer indicates that Singapore Airlines’ security team helped coordinate the response. On June 8, the airline informed the Golden Dragon Institute that it was “coordinating with relevant parties” and had “taken steps to contain the issue.” Singapore Airlines did not provide additional comment to BleepingComputer.
The information shared with BleepingComputer identified several major airlines whose passenger records were stored in the database. However, there is no evidence that any of those airlines operated the exposed system or that their corporate networks were compromised.
Changi Airport Group, which manages and operates Singapore’s Changi Airport, said it had investigated the issue but declined to comment.
BleepingComputer also contacted Vietnamese authorities before publication but did not receive a response.
It remains unknown whether threat actors downloaded, sold, ransomed, or otherwise misused the exposed passenger and crew data before the database was secured. Kinryu Labs said it found no ransom note or unfamiliar index on the cluster and did not identify copies of the data being sold online.
However, without access to server logs, researchers could not conclusively determine whether an unauthorized party copied the information.
Kinryu Labs expects to publish additional technical findings later this week on its blog.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses can drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



