Unsecured Vietnam-linked flight database leaks 220M passenger records
A cloud-based Advance Passenger Information System (APIS) database linked to Vietnam was left exposed, containing 220 million records of passengers and crew from 2017 to 2026. The data included names, passport numbers, birth dates, nationalities, and flight details. Researchers accessed the system using default credentials via a cloud path.
The exposed system was a cloud-hosted Advance Passenger Information System (APIS) associated with Vietnam. It held a massive repository of 220 million entries covering both travelers and flight crew members over a nearly decade-long period, from 2017 through 2026.
Security researchers discovered the vulnerability by locating a cloud path and logging in with default credentials. The compromised dataset contained highly sensitive personal identifiers, including full names, passport numbers, birth dates, nationalities, and specific flight itineraries.
The exposure of such a vast trove of personal and travel data could enable widespread identity theft and sophisticated phishing campaigns. Affected individuals may face risks of passport fraud or unauthorized tracking of their movements. For aviation security, the leak of crew details might pose operational vulnerabilities. This incident underscores how default credentials on cloud infrastructure can turn a single misconfiguration into a massive privacy breach.