Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet
A company left 220 million airline passenger and crew records, including passport numbers and full trip details, open on an unsecured database for years. The data could let attackers steal identities or track people's movements.
- Report priority
- Medium
What is known
- A company running an Advance Passenger Information System left its Elasticsearch database unsecured.
- This system collects flight details and traveler IDs before flights depart.
- The attacker did not need to hack in; the database was publicly accessible online.
- The exposed data included names, birthdates, passport numbers, flight schedules, seat assignments, and baggage info.
- The leak spanned January 2017 to April 2026.
What to do
Check if you traveled by air between January 2017 and April 2026. If you did, your name, birthdate, passport number, flight details, and baggage info may have been exposed. There is no way to confirm if your data was included, but if you used this system, assume it was.
Monitor your accounts for unusual activity, especially travel-related services. If you notice fraud or unauthorized access, contact your bank or the airline. The company that exposed the data has since secured it, but no official recall or fix is available. For identity protection, consider a credit freeze or fraud alert with your local credit bureau.
Reported details
An unsecured Elasticsearch cluster exposed approximately 220.8 million airline passenger and crew records, including passport numbers, full itineraries, and detailed travel histories spanning January 2017 to April 2026. The data originated from an Advance Passenger Information System (APIS), a standardized database airlines use to transmit traveler identity and flight details to border authorities. Exposed fields included names, dates of birth, passport numbers, flight schedules, seat assignments, and transit airport logs, enabling identity fraud, account takeovers, and precise geolocation tracking over nine years.
The vulnerability stemmed from two misconfigurations: the cluster rejected direct internet access with an HTTP 401 error (misleadingly suggesting protection), while an alternative cloud-based endpoint accepted default credentials. Internet scanning services like FOFA flagged the exposed database as early as 2022. Researchers at Kinryu Labs disclosed the issue on June 3, 2026, and the cluster was secured by June 8, 2026, with assistance from Singapore Airlines.
No airline was confirmed as the operator or directly breached.