Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. 220 million traveler records exposed in Vietnam-linked APIS leak

220 million traveler records exposed in Vietnam-linked APIS leak

Scheduled Pinned Locked Moved Cybersecurity News
1 Posts 1 Posters 6 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    An exposed Advance Passenger Information System (APIS) database linked to Vietnamese aviation infrastructure left roughly 220 million passenger and crew records publicly accessible. The cache included names, passport numbers, dates of birth, nationalities, and flight details, with entries spanning 2017 to 2026.

    Researchers found the cloud-hosted system reachable via a public path that still accepted default credentials, allowing unrestricted read access without any authentication bypass or sophisticated exploit. The dataset reportedly covered both passengers and crew members, raising concerns regarding long-term identity theft and targeted phishing campaigns.

    • Exposed data: full names, passport numbers, dates of birth, nationalities, and flight itineraries.
    • Timeframe: records from 2017 through 2026.
    • Root cause: default credentials left active on a cloud-based APIS instance.
    • Access method: direct connection to the exposed system using vendor-default login details.

    The findings underscore persistent risks tied to misconfigured cloud deployments and unchanged factory settings, especially in border-control and travel infrastructure. It remains unclear whether the operator has restricted access or rotated credentials since the disclosure. Travelers whose data may be involved should monitor for unsolicited communications referencing flight history or passport details.

    Source: BleepingComputer

    For those in travel or aviation security, how is your organization auditing cloud-facing systems for default credential usage, and would a discovery like this prompt an immediate review of your APIS or PNR handling procedures?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World