A massive database containing roughly 220 million traveler records linked to Vietnam was exposed through unsecured APIs, potentially revealing personal and travel information belonging to passengers from around the world.
Security researcher Jeremiah Fowler discovered the publicly accessible database, which contained approximately 440 million records totaling more than 106 GB. Around half appeared to contain traveler information, while the remaining records included associated ticketing and travel data.
The exposed information included names, dates of birth, passport numbers and nationalities, along with flight details such as departure and arrival locations, airlines, booking information and travel dates.
Researchers linked the database to APIs associated with Vietnamese travel infrastructure, although the organization responsible for managing the exposed system was not immediately identified. Access to the database was restricted after the exposure was reported.
The combination of identity and travel information creates significant security risks. Criminals could potentially use the data for identity theft, targeted phishing or highly personalized social-engineering attacks.
Travel history can be particularly sensitive because it may reveal behavioral patterns, frequently visited destinations and periods when individuals are away from home. Passport information also represents a long-term risk because it cannot be changed as easily as a compromised password.
There is currently no evidence that criminals accessed or downloaded the exposed information. However, because the database was publicly accessible, researchers cannot determine who may have reached it before access was secured.
The incident also demonstrates the growing security risks surrounding APIs. Travel platforms rely heavily on APIs to exchange passenger information between airlines, booking systems and other services, meaning a poorly protected endpoint can expose enormous amounts of data without requiring attackers to breach the underlying network.
Organizations handling passenger information should ensure that APIs use strong authentication, strict access controls and continuous monitoring. Sensitive information should also be limited to what applications genuinely require rather than being unnecessarily exposed through internet-facing services.
The discovery shows how a single API configuration problem can become a major privacy incident. When hundreds of millions of identity and travel records are involved, even an accidental exposure can create risks that persist long after the original database has been secured.