AI News Feed
Market watch
Cybersecurity

Vietnam-Linked APIS Leak Exposed 220 Million Traveler Records

A Vietnam-linked APIS database exposed over 220 million traveler records before being secured, BleepingComputer reports.

BleepingComputer reported that Kinryu Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity. The cluster, named pax-info, contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries, according to the report.

Kinryu Labs said the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer said it could not confirm which Vietnamese organization operated the system. Researchers said the database was reachable through a chain of security mistakes and default credentials.

The exposed records included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated and actual flight times. BleepingComputer described the information as data typically carried by APIS and related airline systems.

Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian and New Zealand nationality, among others. The researchers could not provide a complete breakdown by nationality. The data covered numerous international airlines across Asia-Pacific, Europe and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryu Labs expects to publish additional details on its blog later this week, according to BleepingComputer.

Editor's Summary

A Vietnam-linked APIS database exposed more than 220 million passenger and crew records spanning 2017 to 2026 before being secured. Kinryu Labs discovered the Elasticsearch cluster through default credentials and other security mistakes, with the data hosted in Viettel-assigned IP space in Hanoi. It remains unclear whether the records were copied or abused.