← Vietnam-linked APIS (unidentified operator)

2026 Vietnam-linked APIS — open Elasticsearch exposed ~220.8M passenger/crew records (Kinryū/BC)

2026 220.8M records affected Share on X

Data compromised

Passenger and crew travel records (~210.3M passenger + ~10.5M crew): names, DOB, sex, nationality, passport/travel-document numbers, expiration dates, issuing countries, flight details. Figures are travel records not unique people. Operator org not identified by BC.

Technical writeup

Independent researcher verification (Kinryū Labs) reported by BleepingComputer — September 8, 2026. An Advance Passenger Information System Elasticsearch cluster named pax-info (~107 GB, 29 indices) was accessible online via misconfigurations. Hosted in Viettel-assigned IP space in Hanoi; BC could not confirm which Vietnamese organization operated it. Combined ~220,783,700 entries (210,318,069 passenger + 10,465,631 crew) spanning roughly Jan 2017–Apr 2026. Major airline passenger rows present; no indication airlines’ own networks were breached. Unclear if data was downloaded/sold before secured; no ransom notes observed. Operator not named — companyConfirmed false; recordsAffected 220783700 from researcher census of travel records.

Root cause

Chain of security misconfigurations exposing Elasticsearch APIS cluster (pax-info) on Viettel-assigned Hanoi IP space

References