Massive airline leak exposes 210 million passenger records

An unprotected APIS database left default credentials active, exposing 210 million airline passenger logs and travel details online.

If you flew through Vietnam between 2017 and 2026, your passport details and flight history may have been exposed in a massive cloud leak. ©Image Credit: Unsplash / Oxana Melis
If you flew through Vietnam between 2017 and 2026, your passport details and flight history may have been exposed in a massive cloud leak. ©Image Credit: Unsplash / Oxana Melis

If you have taken an international flight anytime over the past decade, your travel history and personal information might be making the rounds on the web as we speak. Cybersecurity researchers have discovered a massive misconfigured database sitting wide open online, exposing over 220 million airline passenger and crew records.

Millions of passengers and crew affected

The records floating around include over 210 million (210,318,069 to be precise) passenger entries and over 10 million (exactly 10,465,631) cabin crew data. The total number of passenger and crew members affected in this massive data breach stands at exactly 220,783,700.

The exposed cache, uncovered by cybersecurity firm Kinryū Labs, spans nine years of sensitive travel data logged between January 2017 and April 2026.

Nine years of flight logs left wide open

The leak originated from an Advance Passenger Information System (APIS) database. APIS is the border security data feed that airlines use to transmit passenger details to government border control agencies before departure.

The database cluster, titled “pax-info,” was hosted on IP address space assigned to Vietnamese telecommunications provider Viettel in Hanoi.

Sensitive and personal details exposed

While researchers haven’t confirmed which specific organization operated the server, the data covers travelers of virtually every nationality who flew to, from, or through Vietnam over the nine-year period.

What makes this breach particularly scary isn’t just the sheer number of entries, it’s the depth of the personal information exposed:

  • Personal identity details: Full names, dates of birth, gender and nationalities.
  • Travel document info: Passport numbers, document expiration dates and issuing countries.
  • Detailed itineraries: Airline names, flight numbers, departure and destination airports, transit stops, seat assignments, baggage references and exact flight timestamps.

Because the logs map actual physical movements alongside passport credentials, experts warn that compromised files like these are a goldmine for targeted phishing and identity theft.

Default passwords strike again

So, how did millions of private records end up visible on the open internet? It comes down to a classic case of bad cybersecurity hygiene.

When Kinryū Labs first scanned the primary web address, it returned a standard “401 Unauthorized” error message, giving the illusion that the database was password-protected. However, a secondary cloud access path to the exact same database was left completely unprotected and accepted default credentials.

To make matters worse, web records show that internet scanning platforms had logged the host as far back as October 2022 and identified it as an open database by July 2023. What this means is that it may have been out there in the open for years before anyone noticed.
The fallout and the fix

Kinryū Labs discovered the exposed database on June 3, 2026, and immediately alerted authorities, national emergency response teams and major airlines appearing in the dataset. The cluster was finally locked down by June 8 after Singapore Airlines’ security team stepped in to help coordinate the containment effort.

The good news is that there is no sign that any individual airline’s internal network was hacked or compromised. Researchers also say they found no evidence that the dataset is currently being sold on dark web forums.

The bad news is that, because the server lacked proper access logs, researchers say there is no way to know for sure if bad actors downloaded a copy while it was left wide open.

What to do if you think you may be affected

If you traveled through the region over the last nine years and think you may be affected, keep a sharp eye out for suspicious emails or messages posing as airlines or border agencies.

You should also be on the lookout for unexpected visa or travel-document applications filed in your name, especially if you hold a passport from a country with high-value travel documents like the United States, Britain or Canada.

Sources: TechRadar, Tech insider