Wide-open airline database leaked 220 million passenger records, researchers say

A Vietnam-linked passenger screening system sat on the internet with default logins, exposing nine years of travel data.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial 16:9 image of a large Japanese urban data centre at dusk, exterior shot, rows of cooling units and server ventilation grilles lit by am
Share

Key points

  • Researchers found an Advance Passenger Information System (APIS) database holding 220 million passenger and crew records exposed to the open internet.
  • The records included full names, passport numbers, dates of birth, nationalities and flight itineraries covering 2017 through 2026.
  • The system was reachable through a cloud address using default, factory-set login credentials.
  • The database is linked to Vietnamese aviation infrastructure, though the exact operator has not been publicly named.
  • Anyone who flew on affected routes should assume their passport details may be in criminal hands and watch for targeted scams.

A passenger screening database containing 220 million traveller records was left wide open on the internet, according to researchers who stumbled on it while scanning cloud services. The system is an Advance Passenger Information System, or APIS: the software airlines use to send passenger details to border authorities before a flight lands. This one is linked to Vietnam.

The exposure was first reported by BleepingComputer.

According to the researchers, the database was reachable through a cloud-hosted address and protected only by the default username and password shipped with the software. In other words, no one had changed the factory login. That is the digital equivalent of leaving the key in the door.

What was actually in the database?

Personal and travel data on roughly 220 million people, going back nearly a decade. Each record could include a passenger or crew member's full name, passport number, date of birth, nationality and the specific flights they took. The dates on the records span 2017 to 2026, meaning forward bookings were caught up in the leak too.

Passport numbers are the sensitive part. Unlike a password, you cannot rotate a passport in an afternoon. Criminals use leaked passport data to open accounts, apply for credit, and build convincing impersonation kits for later fraud.

Detail Figure
Records exposed ~220 million
Date range covered 2017 to 2026
System type Advance Passenger Information System (APIS)
Access method Cloud endpoint, default credentials
Country link Vietnam

How did the data get out?

The short answer: someone stood the system up in the cloud and never changed the default login. Researchers found it during routine internet scanning, connected with the known factory credentials, and were able to read the full dataset. No exploit chain. No zero-day, meaning a previously unknown software flaw. Just a door left unlocked.

This pattern is depressingly common. Cloud-hosted databases from vendors like Elasticsearch, MongoDB and various commercial airline back-office products regularly turn up unauthenticated on the public internet. The vendor ships secure defaults on paper. The operator skips the hardening step during deployment.

It is not yet public which airline, ground handler or government contractor was running this specific instance. Researchers say they contacted the party they believed responsible and the database was eventually taken offline.

Should ordinary travellers be worried?

If you flew on Vietnamese routes or Vietnam-bound flights in the last several years, treat your passport number as potentially known to strangers. That does not mean fraud is imminent, but it does raise your baseline risk for a few specific scams.

Watch for emails, texts or calls that claim to be from an airline, an embassy or a border agency and quote your real travel details to sound legitimate. That trick is called phishing, where criminals send fake messages designed to pry loose more information or a payment. Real airlines will not ask you to confirm your passport number by replying to a text.

If your passport shows up in suspicious account-opening attempts, most countries let you flag it with the issuing authority. In the UK that is HM Passport Office. In the US it is the State Department.

The bigger picture

APIS feeds are a required piece of international aviation. Every carrier sends them. That means the security of border data does not rest with border agencies alone: it rests with every airline, handler and IT contractor in the chain. A default password at one small vendor can expose data belonging to passengers of dozens of airlines who never chose to trust that vendor in the first place.

Regulators in the EU and UK have fined companies heavily for exactly this class of failure. Expect scrutiny to follow this one too.

© 2026 Threat Vectr