Skip to main content

Morning Overview

A leaked database left 220 million passenger records open, passport numbers included

A database used to track air travelers before they cross a border sat exposed on the open internet for an unknown length of time, holding more than 220 million records that included passport numbers, names, and flight details. Researchers say the system appears linked to a Vietnamese organization, though the exact operator was never confirmed. Unlike a password, a passport number cannot simply be reset once it has been seen by the wrong people.

The system in question is known as an Advance Passenger Information System, a category of database that airlines and border agencies around the world rely on to collect identity and flight information before travelers arrive at or depart from a country. Because these systems sit at the intersection of aviation and immigration data, the records inside tend to be unusually sensitive, combining travel-document numbers with the kind of biographical detail normally reserved for government files.

How Kinryū Labs Found the Exposed Cluster

The discovery traces back to a research group called Kinryū Labs, which came across the exposed system on June 3 while surveying misconfigured databases as part of unrelated research into ransomware activity. The cluster, an Elasticsearch instance named “pax-info,” contained 29 separate indices totaling roughly 107 gigabytes of data. Its two largest indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries spanning January 2017 through April 2026.

What the Exposed Records Contained

The information sitting in the open database included travelers’ names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Attached to those identity records was a matching set of travel data covering flight numbers and dates, airlines, departure and destination airports, seat assignments, baggage references, and scheduled versus actual flight times. Sample records reviewed by reporters at BleepingComputer included travelers holding Korean, Chinese, Canadian, and New Zealand passports, suggesting the database’s reach extended well beyond Vietnam itself to anyone who had flown to, from, or through the country over nine years.

A Chain of Misconfigurations, Not One Simple Mistake

What made the database reachable was not a single oversight but two stacked ones. Directly from the open internet, the server returned an “Unauthorized” error that should have blocked outside access entirely. However, researchers found a separate, cloud-based path into the same cluster, and once inside through that route, the system accepted default login credentials rather than requiring anything unique. An internet-scanning platform had recorded the host as far back as October 2022, though investigators could not determine when the passenger data itself first became retrievable, meaning the true window of exposure may be considerably longer than the nine years of travel records the database contained.

Notification, Response, and Unanswered Questions

Kinryū Labs said it alerted Vietnamese authorities, the airlines whose passengers appeared in the records, and national computer emergency response teams starting on the day of discovery, and that the exposed access point was shut down five days later. Singapore Airlines’ security team was reported to have coordinated part of that response, telling researchers it had engaged relevant parties and taken steps to contain the issue, while the airport authority managing Singapore’s Changi Airport confirmed it investigated the matter without offering further comment. Vietnamese authorities did not respond to outside inquiries about the system before the findings were published. Because researchers had no access to the server’s own logs, it remains unclear whether anyone copied the data before the hole was closed, and no dataset matching the leak has surfaced for sale on criminal marketplaces so far.

Why the Passport Numbers Are the Lasting Risk

Data breaches involving names and emails tend to fade in relevance once affected accounts are secured, but travel-document numbers carry a longer shadow. Passport numbers are frequently used as secondary identity verification by airlines, hotels, and government services, and unlike a password, most travelers cannot easily change theirs outside of a formal reissuance process tied to loss, theft, or expiration. Combined with birthdates and nationality, the exposed dataset offers enough consistent identifying detail to support impersonation attempts or targeted fraud years after the original leak, even without evidence that the data was actively harvested before the access point closed.

An Unresolved Question About How Long the Door Was Open

One detail investigators could not pin down may matter more than the headline figure of 220 million records. The nine years of travel data inside the cluster describe how far back the records reach, not how long outsiders could actually see them. An internet-scanning platform had already logged the host as a database as far back as July 2023, and the underlying host and port were visible even earlier, in October 2022, which means the misconfiguration that ultimately let researchers in through a cloud-based path could plausibly have existed for years before anyone noticed it. Without access to the server’s own logs, researchers could only confirm that the hole was closed on June 8, not when it first opened, leaving a gap in the record that no amount of after-the-fact remediation can fill.

That uncertainty is compounded by the fact that the exposed totals describe travel records rather than unique travelers. Passengers and crew members who flew multiple times over the nine-year span would appear repeatedly in the database, meaning the true number of distinct people affected is smaller than 220 million, even though each individual record carried the same passport and flight detail regardless of how many times that person appears. Kinryū Labs has said it plans to publish additional technical findings from its investigation, which may eventually clarify how the two misconfigurations lined up and for how long.

This article was created with the assistance of AI and reviewed by an editor.


More from Morning Overview