More than 220 million passenger and crew records were openly reachable through a misconfigured Advance Passenger Information System (APIS) cluster that appears linked to a Vietnamese organization, researchers told BleepingComputer.
Kinryū Labs' discovery and the scope of the leak
Security researchers at Kinryū Labs found an exposed Elasticsearch cluster named "pax-info" on June 3 while surveying internet-accessible databases as part of ransomware research. The cluster contained 29 indices and roughly 107 GB of data. Two principal indices held 210,318,069 passenger records and 10,465,631 crew records — a combined total of 220,783,700 entries spanning January 2017 through April 2026.
What the exposed APIS dataset contained
The dataset mirrored the kind of information APIS systems collect from airlines: passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel metadata included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times. Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality; the researchers noted the records could relate to people from virtually anywhere who flew to, from, or through Vietnam during the nine-year period.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildHow the database was reachable: a chain of misconfigurations
Kinryū Labs reported that the cluster was accessible only after chaining two misconfigurations. From the public internet, the service returned an HTTP 401 "Unauthorized" response, blocking direct access; a separate, cloud-based access path, however, allowed the researchers to reach the cluster, and the system then accepted default credentials. Internet intelligence platform FOFA first logged the host and port in October 2022 and identified the service as a database in July 2023, but Kinryū Labs could not determine when the passenger data first became retrievable via the secondary access path.
Response, attribution, and remaining uncertainties
Kinryū Labs said the cluster was hosted in Viettel-assigned IP address space in Hanoi and that it reported the exposure to Vietnamese authorities, airlines represented in the database, and national computer emergency response teams beginning June 3. Researchers said access to the database was remediated on June 8. An authenticated email reviewed by BleepingComputer shows Singapore Airlines' security team helped coordinate the response, telling Kinryū Labs on June 8 that it had "engaged the relevant parties" and "taken steps to contain the issue." Singapore Airlines did not provide an additional comment to BleepingComputer.
BleepingComputer contacted Vietnamese authorities in advance of publication but received no response. Changi Airport Group said it had investigated the matter but declined to comment. The reporting identifies several major airlines whose passenger records appeared in the database, but there is no indication the airlines operated the exposed system or that their own networks were compromised.
What this means for travelers, security teams, and airlines
- Travelers: The exposed fields include personally identifying information and passport numbers for records tied to trips through Vietnam from January 2017 to April 2026. That combination of identity and travel detail is precisely the data that can be abused for identity theft or targeted fraud if copied and misused.
- Security teams and cloud engineers: The incident underlines the risk of chained misconfigurations and the danger of default credentials being accepted once an alternate access path is available. FOFA's logs show the host and port were visible in October 2022, and the service was recognized as a database by July 2023; however, researchers could not determine how long the data was retrievable through the secondary path.
- Airlines and airports: Airlines whose records appear in the dataset have been notified, and at least one carrier — Singapore Airlines — assisted in containment coordination. Airports and carriers will need to determine whether their shipment of passenger data to third-party systems is properly secured and whether further operational or notification steps are required.
Kinryū Labs said it found no ransom notes or unfamiliar indices on the cluster and could not identify the dataset being offered for sale online, but without access to server logs researchers could not conclusively determine whether anyone had copied the data prior to remediation. The researchers indicated they expect to publish additional technical findings on their blog later this week. The central unanswered, factual point remains whether server-side logs will ever reveal whether the 220,783,700 entries were exfiltrated before containment.




