220 Million Traveler Records Exposed in Vietnam Cloud Database Misconfiguration
A misconfigured cloud database in Vietnam exposed about 220 million passenger and crew records spanning 2017–2026, including passport and travel details, according to TechRadar.
The researchers, from Kinryū Labs, said the database was an Elasticsearch cluster that was not reachable from the open internet but could be accessed through an alternate, cloud-based route. Once inside, the cluster accepted default credentials, granting access to an archive of 29 indices weighing about 107GB. The archive appeared to stem from an Advance Passenger Information System (APIS), which airlines use to submit passenger and crew data to national authorities before departure or arrival for border control.
Beyond names, birth dates, nationalities and passport or travel document numbers, the exposed data also contained individuals' sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, and baggage references. The researchers found 210,318,069 passenger records and 10,465,631 crew records in two large indices. Because the records were tied to trips rather than to individual travelers, a person who flew several times could appear multiple times in the archive.
Affected individuals included nationals of Canada, China, South Korea, and New Zealand, the researchers said, and airlines from Asia-Pacific, Europe, and the Middle East were referenced in the data. The operator and owner of the database could not be identified, but the cluster was hosted in Viettel-assigned IP space in Hanoi.
On June 3, Kinryū Labs reported the exposure to Vietnamese authorities, the affected airlines, and the country's CERT. The archive was locked down on June 8. According to BleepingComputer, Singapore Airlines' security team took the lead on remediation, saying they had "engaged the relevant parties" and taken steps to contain the issue. The researchers said they found no evidence that the data had been put up for sale on the dark web or that a hacking group had claimed responsibility, but a full forensic audit would be needed to determine whether information had been stolen.
Misconfigured cloud databases remain one of the leading causes of data leaks, security experts say. Cassius Edison, COO of Closed Door Security, said many organizations fail to maintain full visibility of their IT systems and skip proper audits, which "inevitably leads to oversights in security and monitoring." He recommended hiring independent penetration testers and security auditors, especially at large firms where teams often work independently.
The Vietnamese leak adds to a year of major exposure incidents. In 2026 alone, Infutor, a data-driven consumer identity management company, left more than 670 million identity records exposed, and another misconfigured MongoDB database exposed over three billion records.