Vietnam-linked APIS Elasticsearch leak: 220.8M passenger/crew travel records
BleepingComputer exclusive (8 September 2026): Kinryū Labs found an internet-reachable Elasticsearch cluster named "pax-info" (Viettel-assigned IP space, Hanoi) holding Advance Passenger Information System (APIS) data — 210,318,069 passenger and 10,465,631 crew records (220,783,700 entries, ~107 GB across 29 indices) spanning January 2017 to April 2026. Fields included names, dates of birth, sex, nationalities, passport/travel-document numbers and expiry, issuing countries, plus flight numbers/dates, airlines, origin/destination/transit airports, seats, baggage refs, and scheduled/estimated/actual times. Sample records reviewed included Korean, Chinese, Canadian, and New Zealand nationalities among others; many international carriers across Asia-Pacific, Europe, and the Middle East appear, so travellers who flew to/from/through Vietnam may be affected (counts are travel records, not unique people). Access path: open internet returned HTTP 401, but a cloud-based path reached the cluster which then accepted default credentials (FOFA saw the host/port from Oct 2022; exposure duration via the second path unknown). Kinryū reported to Vietnamese authorities, airlines, and national CERTs from 3 June 2026; access remediated 8 June 2026 after Singapore Airlines security helped coordinate containment. No ransom notes or sales listings found; without server logs, prior copying cannot be ruled out. Operator organisation not confirmed. Kinryū expects a fuller technical write-up on its blog later this week. Primary wire: BleepingComputer; researcher: Kinryū Labs.
- Exploited in Australia?
- unknown
Primary: BleepingComputer — Vietnam-linked APIS leak (8 Sep 2026) · Vendor: Kinryū Labs reports (technical write-up pending) · Kinryū Labs
