If You Traveled Through Vietnam Since 2017, Your Passport Number and Every Flight You Took Were Exposed

A Vietnam-linked database exposed 220 million traveler records, including passport details and other sensitive data, putting millions of travelers at risk of identity theft.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

A new discovery by security firm Kinryū Labs has uncovered a Vietnam-linked database containing 220 million passenger and crew records, with the exposed data spanning travelers who flew to, from, or through Vietnam between January 2017 and April 2026.[1]

If you traveled to Vietnam during this period, there’s a chance your personal and travel information is among the exposed records, including your name, date of birth, nationality, passport and number. The database also contained flight numbers and dates, airlines, departure and destination airports, seat assignments, baggage references, and flight times.

And this isn’t just basic travel information. Attackers could use these details to craft highly convincing phishing campaigns that could lead to identity theft and financial fraud.

Here’s how the data was leaked and the steps you can take to protect yourself.

In this article
What the exposed records revealed
How authorities responded to the data leak
The risks of exposing this much personal data
What can you do to protect yourself
Bottom line

What the exposed records revealed

As reported by BleepingComputer, Kinryū Labs found the exposed database containing 220 million Advanced Passenger Information System (APIS) records on June 3.

APIS allows governments to collect traveler and flight data from airlines before passengers and crew arrive at or depart from a country, allowing border and immigration authorities to verify people ahead of time.

The database, an Elasticsearch cluster named PaxInfo, could be reached through a chain of vulnerabilities. When accessed from the open internet, the endpoint returned an HTTP 401 error.

However, the researchers found a secondary cloud-based access path that allowed them to access the cluster using default login credentials.

Kinryū Labs further cross-checked the leaked data with their own team’s travel history to Vietnam. The breached information contains 220,783,700 entries, including 210,318,069 passenger records and 10,465,631 crew records.

These are not unique individual details, but the number of travel records. This means that if you have traveled multiple times to Vietnam during this period, you might appear several times within these records.

As per the researchers, the cluster was hosted in Viettel IP space in Hanoi. However, the exact organization controlling it couldn’t be confirmed by either Kinryū Labs or BleepingComputer.

Internet scanning platform Focus On Fixed Assets (FOFA) had first indexed the host in October 2022 and flagged it as a database in July 2023. However, neither Kinryū Labs nor any other researcher could determine when the data became accessible through the second cloud-based path.

This means that the data could even span farther back than the initially suspected nine-year period.

The breached information includes the following details belonging to passengers and crew:

  • Names and sex
  • Dates of birth
  • Nationalities
  • Passport or travel document numbers
  • Document expiration dates and issuing countries
  • Travel data such as flight numbers and dates, airlines, destinations, seats, baggage, actual flight times, and other airline system data

BleepingComputer reviewed some of the samples and found information pertaining to various nationalities, such as Korean, Canadian, New Zealand, and Chinese. However, this is not an exhaustive list, and the data covers various international airlines across the Middle East, Europe, and Asia-Pacific.

This means that if you have flown to Vietnam since January 2017, chances are that your data is among this leaked database.

Kinryū Labs also didn’t find any ransom notes or unfamiliar indices on the cluster. They also couldn’t rule out any prior unauthorized access due to the lack of server logs.

How authorities responded to the data leak

Kinryū Labs promptly disclosed the exposure to Vietnamese authorities, the National Computer Emergency Response Team (CERT), and the airline whose passenger records appeared in the database.

Following this, access to the database was remediated on June 8, which means that the cloud-based access path that allowed researchers to bypass the 401 error was closed. But this doesn’t mean that the data was deleted or secured elsewhere, nor does it confirm that nobody got hold of the data before it was remediated.

Vietnamese authorities didn’t respond to Kinryū Labs’ outreach or BleepingComputer’s request for comment. However, Singapore Airlines’ security team confirmed that it’s actively helping coordinate the response and has engaged relevant parties and taken steps to contain the issue.

The risks of exposing this much personal data

A data leak of this magnitude could lead to personalized phishing attacks. For instance, you might receive an email claiming to be from an airline carrier with accurate details about your passport number and past travel records, thereby convincing you that the sender is legitimate.

However, such messages usually contain a malicious link, which, when clicked, can install malware or spyware on your device or even steal your credentials through fake login pages.

Additionally, malicious actors could use the leaked data to steal your identity. Details such as your name, date of birth, and passport number may be used to create bogus passports or travel documents. Alternatively, scammers might use some of your details to create entirely new synthetic identities.

Identity theft could even lead to financial fraud if the scammer files fraudulent returns in your name or takes out a new line of credit without your knowledge.

Moreover, scammers may also file fake and fraudulent travel insurance claims in the victim’s name by using the real flight number, baggage reference, and accurate dates from the past.

What can you do to protect yourself

At the time of writing, there’s no way for you to check if your information is in the leaked database, but here are a few steps you should take to secure your digital privacy if you’ve traveled through Vietnam in the recent past.

  1. Check your airline logins: Log in to your airline loyalty account, such as your frequent flyer account, and check your recent transaction history for any unauthorized redemptions or transfers you did not make. These airline miles or points are common targets since they could be converted into hotel stays, flights, or even cash via third-party marketplaces. If you find anything suspicious, alert the airline immediately.
  2. Use a third-party antivirus program: Many top antivirus solutions come with real-time web protection, which can flag suspicious or malicious links before you open them. They can also block access to dangerous URLs and suspicious websites, helping prevent you from accidentally handing over your credentials or personal information to a phishing site.
  3. Be wary of phishing links: If you receive an unexpected message claiming to be from an airline, government agency, or other official organization, don’t panic or act immediately. Scammers often use fear, urgency, or greed to pressure you into clicking a link or sharing information. Inspect the URL carefully, and if you’re unsure about a message, contact the organization directly through its official website or another trusted channel.
  4. Use an identity theft protection service: Getting identity theft protection amid the risk of massive data leaks makes a lot of sense. These tools can scan known leaked databases and the dark web to look for your personally identifiable information and alert you if they find anything. They can also help you restore your identity in case of an identity breach.

Bottom line

Your personal details and passport number could already be out there if you traveled to Vietnam during the period covered by the database. There’s no concrete way of confirming this, but the threat of identity theft and fraud looming makes it better to take precautions now than wait until your information is misused.

Consider using an antivirus that comes with real-time web protection, an identity theft protection service to help prevent the misuse of your data, and good cybersecurity hygiene by being suspicious of unexpected messages and emails, using 2FA, and verifying communications that claim to come from official organizations.

4.8
Editorial Rating
Get Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] 220 million traveler records exposed in Vietnam-linked APIS leak