All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
A new discovery by security firm Kinryū Labs has uncovered a Vietnam-linked database containing 220 million passenger and crew records, with the exposed data spanning travelers who flew to, from, or through Vietnam between January 2017 and April 2026.[1]
If you traveled to Vietnam during this period, there’s a chance your personal and travel information is among the exposed records, including your name, date of birth, nationality, passport and number. The database also contained flight numbers and dates, airlines, departure and destination airports, seat assignments, baggage references, and flight times.
And this isn’t just basic travel information. Attackers could use these details to craft highly convincing phishing campaigns that could lead to identity theft and financial fraud.
Here’s how the data was leaked and the steps you can take to protect yourself.
How authorities responded to the data leak
The risks of exposing this much personal data
What can you do to protect yourself
Bottom line
What the exposed records revealed
As reported by BleepingComputer, Kinryū Labs found the exposed database containing 220 million Advanced Passenger Information System (APIS) records on June 3.
APIS allows governments to collect traveler and flight data from airlines before passengers and crew arrive at or depart from a country, allowing border and immigration authorities to verify people ahead of time.
The database, an Elasticsearch cluster named PaxInfo, could be reached through a chain of vulnerabilities. When accessed from the open internet, the endpoint returned an HTTP 401 error.
However, the researchers found a secondary cloud-based access path that allowed them to access the cluster using default login credentials.
Kinryū Labs further cross-checked the leaked data with their own team’s travel history to Vietnam. The breached information contains 220,783,700 entries, including 210,318,069 passenger records and 10,465,631 crew records.
These are not unique individual details, but the number of travel records. This means that if you have traveled multiple times to Vietnam during this period, you might appear several times within these records.
As per the researchers, the cluster was hosted in Viettel IP space in Hanoi. However, the exact organization controlling it couldn’t be confirmed by either Kinryū Labs or BleepingComputer.
Internet scanning platform Focus On Fixed Assets (FOFA) had first indexed the host in October 2022 and flagged it as a database in July 2023. However, neither Kinryū Labs nor any other researcher could determine when the data became accessible through the second cloud-based path.
This means that the data could even span farther back than the initially suspected nine-year period.
The breached information includes the following details belonging to passengers and crew:
- Names and sex
- Dates of birth
- Nationalities
- Passport or travel document numbers
- Document expiration dates and issuing countries
- Travel data such as flight numbers and dates, airlines, destinations, seats, baggage, actual flight times, and other airline system data
BleepingComputer reviewed some of the samples and found information pertaining to various nationalities, such as Korean, Canadian, New Zealand, and Chinese. However, this is not an exhaustive list, and the data covers various international airlines across the Middle East, Europe, and Asia-Pacific.
This means that if you have flown to Vietnam since January 2017, chances are that your data is among this leaked database.
Kinryū Labs also didn’t find any ransom notes or unfamiliar indices on the cluster. They also couldn’t rule out any prior unauthorized access due to the lack of server logs.
How authorities responded to the data leak
Kinryū Labs promptly disclosed the exposure to Vietnamese authorities, the National Computer Emergency Response Team (CERT), and the airline whose passenger records appeared in the database.
Following this, access to the database was remediated on June 8, which means that the cloud-based access path that allowed researchers to bypass the 401 error was closed. But this doesn’t mean that the data was deleted or secured elsewhere, nor does it confirm that nobody got hold of the data before it was remediated.
Vietnamese authorities didn’t respond to Kinryū Labs’ outreach or BleepingComputer’s request for comment. However, Singapore Airlines’ security team confirmed that it’s actively helping coordinate the response and has engaged relevant parties and taken steps to contain the issue.
The risks of exposing this much personal data
A data leak of this magnitude could lead to personalized phishing attacks. For instance, you might receive an email claiming to be from an airline carrier with accurate details about your passport number and past travel records, thereby convincing you that the sender is legitimate.
However, such messages usually contain a malicious link, which, when clicked, can install malware or spyware on your device or even steal your credentials through fake login pages.
Additionally, malicious actors could use the leaked data to steal your identity. Details such as your name, date of birth, and passport number may be used to create bogus passports or travel documents. Alternatively, scammers might use some of your details to create entirely new synthetic identities.
Identity theft could even lead to financial fraud if the scammer files fraudulent returns in your name or takes out a new line of credit without your knowledge.
Moreover, scammers may also file fake and fraudulent travel insurance claims in the victim’s name by using the real flight number, baggage reference, and accurate dates from the past.
What can you do to protect yourself
At the time of writing, there’s no way for you to check if your information is in the leaked database, but here are a few steps you should take to secure your digital privacy if you’ve traveled through Vietnam in the recent past.
- Check your airline logins: Log in to your airline loyalty account, such as your frequent flyer account, and check your recent transaction history for any unauthorized redemptions or transfers you did not make. These airline miles or points are common targets since they could be converted into hotel stays, flights, or even cash via third-party marketplaces. If you find anything suspicious, alert the airline immediately.
- Use a third-party antivirus program: Many top antivirus solutions come with real-time web protection, which can flag suspicious or malicious links before you open them. They can also block access to dangerous URLs and suspicious websites, helping prevent you from accidentally handing over your credentials or personal information to a phishing site.
- Be wary of phishing links: If you receive an unexpected message claiming to be from an airline, government agency, or other official organization, don’t panic or act immediately. Scammers often use fear, urgency, or greed to pressure you into clicking a link or sharing information. Inspect the URL carefully, and if you’re unsure about a message, contact the organization directly through its official website or another trusted channel.
- Use an identity theft protection service: Getting identity theft protection amid the risk of massive data leaks makes a lot of sense. These tools can scan known leaked databases and the dark web to look for your personally identifiable information and alert you if they find anything. They can also help you restore your identity in case of an identity breach.
Bottom line
Your personal details and passport number could already be out there if you traveled to Vietnam during the period covered by the database. There’s no concrete way of confirming this, but the threat of identity theft and fraud looming makes it better to take precautions now than wait until your information is misused.
Consider using an antivirus that comes with real-time web protection, an identity theft protection service to help prevent the misuse of your data, and good cybersecurity hygiene by being suspicious of unexpected messages and emails, using 2FA, and verifying communications that claim to come from official organizations.