Massive APIS Database Exposes 220 Million Air Passenger Records Online
A critical security lapse has left an **Advance Passenger Information System (APIS)** database, containing over 220 million passenger and crew records, openly accessible online. Discovered by **KinryΕ« Labs**, the exposed data includes sensitive details like passport numbers and flight itineraries, spanning nine years of travel to, from, or through Vietnam.
A significant cybersecurity incident has come to light, revealing an **Advance Passenger Information System (APIS)** database containing over 220 million passenger and crew records was openly accessible online. The system, reportedly linked to a Vietnamese organization, exposed a trove of sensitive data due to a series of security misconfigurations.
**APIS** are globally deployed systems that collect essential identity, passport, and flight information from airlines before passengers and crew reach their destination or depart a country. The exposed records cover a vast period from January 2017 to April 2026, potentially impacting travelers of numerous nationalities who transited through Vietnam.
## Nine Years of Compromised Travel Data
**KinryΕ« Labs** stumbled upon the exposed **Elasticsearch** cluster, dubbed 'pax-info', on June 3 during their research into ransomware activities. The cluster contained 29 indices and approximately 107 GB of data, with its two primary indices holding 210,318,069 passenger records and 10,465,631 crew records, totaling 220,783,700 entries.
According to **KinryΕ« Labs**, the cluster was hosted within **Viettel-assigned IP space** in Hanoi. While the specific Vietnamese operator remains unconfirmed, the implications for global travelers are substantial.
The compromised information includes full names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries for both passengers and crew members.
Associated travel data encompassed flight numbers and dates, airlines, departure, destination, and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times β data typically managed by **APIS** and related airline systems.
Sample records reviewed by BleepingComputer indicated travelers of Korean, Chinese, Canadian, and New Zealand nationalities, among others. The data involved numerous international airlines operating across Asia-Pacific, Europe, and the Middle East, suggesting a broad impact on global travelers.

**KinryΕ« Labs** confirmed the legitimacy of the data by cross-referencing records with their own travel history to Vietnam. It's important to note that the figures represent travel records, meaning individuals who flew multiple times may have multiple entries in the database.
## Chained Misconfigurations Led to Exposure
**KinryΕ« Labs** explained that they gained access to the database by exploiting a chain of two misconfigurations. Initially, the endpoint returned an HTTP 401 "Unauthorized" response, blocking direct access. However, a cloud-based path allowed researchers to reach the cluster, which then accepted default credentials.
Internet intelligence platform **FOFA** first logged the host and port in October 2022, identifying it as a database in July 2023. The exact duration of the database's vulnerability via the second access path remains unknown.
**KinryΕ« Labs** promptly reported the vulnerability to Vietnamese authorities, affected airlines, and national computer emergency response teams starting June 3. Access to the database was reportedly remediated on June 8.
An authenticated email confirmed that **Singapore Airlines'** security team assisted in coordinating the response, informing **KinryΕ« Labs** on June 8 that they had "engaged the relevant parties" and "taken steps to contain the issue." **Singapore Airlines** declined further comment.
While several major airlines' passenger records were found in the database, there is no evidence to suggest that these airlines operated the exposed system or that their own networks were compromised. **Changi Airport Group** also investigated the matter but declined to comment.
Vietnamese authorities did not respond to inquiries. It is currently unclear whether malicious actors accessed, downloaded, sold, or exploited the database before it was secured. **KinryΕ« Labs** found no ransom notes or unfamiliar indices and could not locate the dataset for sale online. However, without server logs, a definitive conclusion on data exfiltration remains elusive.
**KinryΕ« Labs** plans to release additional technical findings on their [blog](https://kinryu.sh/reports/) later this week.