Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
A Vietnam-linked flight database was left open online, exposing 220 million passenger records including passport numbers and flight details. Anyone with the right tools could access this data without permission.
- Report priority
- Medium
What to do
Check if you traveled internationally between January 2017 and April 2026. If you flew, or through Vietnam during that time, your flight and passport details may be in the exposed database. There is no way to confirm whether your data was accessed or stolen.
Monitor your accounts for unusual activity, especially financial or travel-related. If you notice any suspicious transactions or unauthorized access, contact your bank and the airline you used. For more details, check the original report from SecurityAffairs or contact Vietnamese aviation authorities if needed.
Reported details
A Vietnam-linked Advance Passenger Information System (APIS) database was exposed, leaking 220.8 million passenger and crew records spanning January 2017 to April 2026. The exposed Elasticsearch cluster, named "pax-info," contained 29 indices and ~107 GB of data, including passport numbers, full names, dates of birth, nationalities, flight itineraries, seat assignments, and baggage details. The server was hosted on IP addresses tied to Viettel in Hanoi, though the exact Vietnamese operator remains unconfirmed.
The breach exposed sensitive travel data for travelers from Asia-Pacific, Europe, and the Middle East, as the system processed flights to, from, and through Vietnam. Researchers verified the data's authenticity by cross-referencing their own travel records. Frequent travelers may appear multiple times, but the dataset includes non-unique entries rather than a count of distinct individuals.