220M Traveller Records Exposed Because of Default Passwords: Nine Years of Passport and Flight Data at Risk

Security breach in Vietnam-linked APIS database raises concerns over passenger data safety

Passport and cards
220 million passenger and crew records exposed: default credentials put travel data at risk Photo by DΛVΞ GΛRCIΛ: Pexels

More than 220 million passenger and crew records were reportedly left exposed through a Vietnam-linked Advance Passenger Information System (APIS), raising concerns over the security of passport and travel data collected over almost a decade.

Researchers reportedly found an exposed Elasticsearch database accessible through a cloud-based path that accepted default credentials.

The information reportedly included names, dates of birth, nationalities, passport or travel-document numbers and detailed flight information, including seat numbers and baggage references. The database was later secured, although available reporting does not establish whether the information was used for fraud or other criminal activity.

The reported record total should not be interpreted as 220 million individual victims. Researchers said it remains unclear how many unique passengers and crew members are represented in the database, so the number of records should not be treated as a confirmed count of affected people.

What the Exposed Traveller Database Contained

The exposed system was reportedly an APIS database, a type of system used to handle passenger information associated with international travel. APIS data can contain identity and journey information, including details associated with travel documents and individual flights.

According to the reporting, the exposed records included names, dates of birth, nationalities and passport numbers, alongside flight details. Researchers also reported information relating to seats and baggage.

The records reportedly covered passengers and crew travelling to, from or through Vietnam from January 2017 through April 2026. There is no confirmed public breakdown showing how many people from the UK or other individual countries appear in the database.

The available reporting does not establish that payment card details, airline account passwords or loyalty programme credentials were included. It is therefore safer not to describe those categories as compromised.

There is also an important distinction between the database being accessible and evidence that criminals obtained the entire dataset. Reporting indicates that researchers could access the information, while the availability of access logs was reportedly limited, making it difficult to determine whether records had previously been copied by unauthorised parties.

Default Credentials Put Passport Data at Risk

The reported exposure involved a chain of security misconfigurations, including a cloud-based access path that accepted default credentials, rather than a confirmed software vulnerability affecting a named airline product.

That distinction matters because the incident does not currently provide evidence that a particular airline application or reservation platform was inherently defective.

The database was reportedly accessible online before the exposure was addressed. Researchers reportedly discovered the exposed database on 3 June, and the system was secured on 8 June after the exposure was reported. Public reports about the incident appeared on 8 September.

The precise organisation operating the database has not been publicly identified in the available reporting. The system has been described as Vietnam-linked, but that does not by itself establish that Vietnam's government, a particular airline or any named travel company was responsible for the exposure.

For travellers, the main concern is the potential use of authentic travel information in targeted scams. Exposed travel information could potentially make targeted phishing or impersonation attempts more convincing by giving an attacker genuine details about a person's journey.

However, available reporting does not establish that such activity occurred as a result of this exposure.

People who travelled through the affected system should therefore be cautious with unexpected messages referring to flights, passport documents, refunds or travel arrangements.

Requests for sensitive information should be checked independently through an airline or travel provider's official website rather than through links contained in unsolicited messages.

The incident also illustrates why organisations handling passenger information need to remove default credentials before systems are exposed to the internet and maintain access monitoring. Where detailed logs are unavailable, determining whether exposed information was downloaded can become considerably harder.

The full impact remains uncertain. The available evidence does not establish that every record was accessed or misused, while the identity of the organisation responsible and the number of unique individuals represented in the database have not been confirmed.

Further information from the organisation operating the system or relevant authorities would be needed to establish the final scope.


Frequently Asked Questions

  • What is the APIS database?
    APIS is a system used to handle passenger information associated with international travel, containing identity and journey information.
  • What information was exposed in the traveller database?
    The exposed information included names, dates of birth, nationalities, passport numbers, and flight details such as seat numbers and baggage references.
  • Was payment information compromised in the exposure?
    There is no confirmed evidence that payment card details, airline account passwords, or loyalty programme credentials were included in the exposed data.
  • What should travellers do if they suspect their data was exposed?
    Travellers should be cautious with unexpected messages referring to flights or travel arrangements and verify requests for sensitive information through official channels.