220 million traveler records exposed in Vietnam-linked APIS leak

Summary: Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. [...]

A massive database containing roughly 220 million traveler records linked to Vietnam was exposed through unsecured APIs, potentially revealing personal and travel information belonging to passengers from around the world.

Security researcher Jeremiah Fowler discovered the publicly accessible database, which contained approximately 440 million records totaling more than 106 GB. Around half appeared to contain traveler information, while the remaining records included associated ticketing and travel data.

The exposed information included names, dates of birth, passport numbers and nationalities, along with flight details such as departure and arrival locations, airlines, booking information and travel dates.

Researchers linked the database to APIs associated with Vietnamese travel infrastructure, although the organization responsible for managing the exposed system was not immediately identified. Access to the database was restricted after the exposure was reported.

The combination of identity and travel information creates significant security risks. Criminals could potentially use the data for identity theft, targeted phishing or highly personalized social-engineering attacks.

Travel history can be particularly sensitive because it may reveal behavioral patterns, frequently visited destinations and periods when individuals are away from home. Passport information also represents a long-term risk because it cannot be changed as easily as a compromised password.

There is currently no evidence that criminals accessed or downloaded the exposed information. However, because the database was publicly accessible, researchers cannot determine who may have reached it before access was secured.

The incident also demonstrates the growing security risks surrounding APIs. Travel platforms rely heavily on APIs to exchange passenger information between airlines, booking systems and other services, meaning a poorly protected endpoint can expose enormous amounts of data without requiring attackers to breach the underlying network.

Organizations handling passenger information should ensure that APIs use strong authentication, strict access controls and continuous monitoring. Sensitive information should also be limited to what applications genuinely require rather than being unnecessarily exposed through internet-facing services.

The discovery shows how a single API configuration problem can become a major privacy incident. When hundreds of millions of identity and travel records are involved, even an accidental exposure can create risks that persist long after the original database has been secured.

Key facts

  • An exposed APIS database contained 220 million passenger and crew records
  • The exposed data included names, passport numbers, dates of birth, nationalities, and flight details
  • The records spanned from 2017 to 2026
  • Researchers accessed the Vietnam-linked system via a cloud path using default credentials

Why it matters

This massive leak of sensitive traveler data highlights critical vulnerabilities in how passenger information is stored and secured by systems involved in border control and travel facilitation. The accessibility through default credentials points to significant operational security lapses, potentially impacting trust in national travel security infrastructure and exposing individuals to identity theft and other risks.