Slashdot
Follow
220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak
A misconfigured Advance Passenger Information System (APIS) database linked to Vietnam exposed over 220 million passenger and crew travel records. This vast dataset spanned from 2017 to 2026 and contained sensitive personal and travel information. Details included full names, passport numbers, nationalities, flight schedules, seat assignments, and baggage references. Researchers discovered the Elasticsearch cluster containing this data on June 3rd. The cluster was accessible due to a series of security oversights and the use of default credentials. The database has since been secured following its disclosure. However, it remains unknown if the exposed data was previously copied or misused. The exposed information also included dates of birth, sex, and passport expiration dates. Travel data encompassed flight details, airlines, departure and arrival airports, and flight times. Travelers from numerous nationalities were identified in sample records, indicating a broad international scope. The exposed records could potentially impact individuals from anywhere who traveled to or transited through Vietnam.