An exposed Advance Passenger Information System database made more than 220 million passenger and crew travel records accessible online, potentially affecting travelers from many countries who flew to, from, or through Vietnam. Researchers found a misconfigured Elasticsearch cluster named 'pax-info' reachable through a chained access path: the internet-facing service returned HTTP 401, but an alternate cloud path allowed access with default credentials. The data spanned January 2017 to April 2026 and included names, dates of birth, nationalities, passport numbers, document details, flight numbers, routes, seat assignments, baggage references, and flight times. Researchers say the database was in Viettel IP space and access was remediated on June 8.
Why it matters: This exposed highly sensitive identity and travel data that could be abused for fraud, phishing, identity theft, or travel-related targeting. Travelers and airlines potentially affected should watch for impersonation and scam attempts, while operators of travel and border systems should audit internet exposure, cloud routing, and default credentials immediately.
Ax Sharma
2026.09.08
100% relevant
This article appears to be the first tracked report of this specific APIS database exposure involving 220.8 million travel records linked to Vietnam.
← Back to all stories