More than 220 million passenger and crew records containing sensitive travel and passport information were exposed online through a series of security misconfigurations in a database apparently linked to Vietnam.
The exposed database contained 220,783,700 records covering travel activity between January 2017 and April 2026. Researchers from Kinryū Labs discovered the Elasticsearch cluster on June 3 while investigating exposed databases during research into ransomware activity.
The database, named “pax-info,” contained 29 indexes and about 107 GB of data. Two of its main indexes contained more than 210 million passenger records and over 10 million crew records.
The exposed information included names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. The database also contained detailed flight information, including flight numbers, airlines, departure and destination airports, transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times.
Kinryū Labs said the cluster was hosted in IP address space assigned to Viettel in Hanoi. However, the researchers could not confirm which Vietnamese organization operated the system. BleepingComputer also noted that the presence of records from major airlines does not mean those airlines operated the exposed database or that their own networks were compromised.
The researchers verified that the records were genuine by matching information in the database against their own travel to Vietnam. Sample records reviewed by BleepingComputer included travelers from countries such as South Korea, China, Canada, and New Zealand, while the database contained information associated with airlines operating across Asia-Pacific, Europe, and the Middle East.
The number of records does not represent 220 million individual people because passengers and crew members who traveled multiple times could appear repeatedly in the database.
The exposure was caused by a chain of security misconfigurations. The database’s internet-facing endpoint initially returned a 401 “Unauthorized” response, but researchers discovered another cloud-based route that allowed them to reach the cluster. The system then accepted default credentials, providing access to the database.
Internet intelligence platform FOFA had already recorded the host and port in October 2022 and identified the service as a database in July 2023. However, Kinryū Labs could not determine when the passenger information first became accessible through the secondary path.
That means the records cover more than nine years, but the exact period during which they were publicly accessible remains unknown.
Kinryū Labs began notifying Vietnamese authorities, affected airlines, and national computer emergency response teams on June 3. The researchers said access was remediated by June 8.
BleepingComputer reported that Singapore Airlines’ security team helped coordinate the response and confirmed that relevant parties had been engaged and steps had been taken to contain the issue. The airline did not provide additional comments.
It is still unknown whether attackers downloaded or otherwise abused the information before the database was secured. Kinryū Labs said it did not find ransom notes or unfamiliar indexes in the cluster and could not identify evidence that the dataset had been offered for sale online. However, because the researchers did not have access to server logs, they could not determine whether someone had copied the exposed data.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Kinryū Labs is expected to publish additional technical details about the discovery and exposure.



