Airline Data Breach Exposes 220 Million Passenger and Crew Records

Share

- Advertisement -
  • Around 220 million passenger and crew records were exposed through a misconfigured database in Vietnam.
  • The information reportedly included passport details, names, birth dates, nationalities and flight information.
  • Researchers reported the database to authorities and affected organisations, and it was secured several days later.
  • There is currently no confirmed evidence that criminals accessed or sold the exposed information.

A major airline data breach has exposed information linked to around 220 million passenger and crew records, highlighting once again how dangerous poorly secured databases can become when sensitive travel information is stored in the cloud.

Security researchers from Kinryū Labs discovered the exposed database in June 2026. The system was an Elasticsearch cluster containing approximately 107GB of data spread across 29 indices. Although the database was not directly visible on the public internet, researchers found an alternative cloud based route that provided access.

The bigger problem came after they reached the system. The Elasticsearch environment reportedly accepted default credentials, allowing researchers to enter an archive containing years of aviation related information.

The exposed records covered people who had travelled to, from, or through Vietnam between January 2017 and April 2026. The information reportedly came from an Advance Passenger Information System, commonly known as APIS.

Airlines and other travel operators use APIS platforms to collect passenger and crew information before flights. Authorities can then use that information for border control, immigration and other security procedures.

Because of the nature of the system, the exposed information was considerably more sensitive than an ordinary customer database.

- Advertisement -

Passport and travel information among exposed data

The database reportedly contained 210,318,069 passenger records and another 10,465,631 crew records.

Importantly, those figures do not necessarily represent 220 million individual people. Someone who travelled several times could appear in the database multiple times.

The information reportedly included names, dates of birth, nationalities and passport or travel document numbers. Researchers also found additional travel information, including document expiry dates, issuing countries, airline details, departure and destination airports, transit locations, seat assignments and baggage references.

That combination makes the incident particularly concerning.

A leaked email address or telephone number can already create problems for victims. Travel records containing passport details, dates of birth and movement information can provide attackers with much more useful material for impersonation, targeted phishing and identity fraud.

The records were also not restricted to one airline. Researchers reportedly identified references to airlines operating across the Asia Pacific, European and Middle Eastern regions.

- Advertisement -

Among the nationalities appearing in the data were Canadian, Chinese, Korean and New Zealand citizens.

However, researchers were unable to determine exactly which organisation operated the APIS database or who was responsible for maintaining the exposed infrastructure.

The server was hosted within IP space assigned to Viettel in Hanoi, Vietnam, but that alone did not establish ownership of the database.

Researchers reported the exposure to authorities

Kinryū Labs reported its findings on June 3 to Vietnamese authorities, the country’s computer emergency response organisation and airlines referenced within the exposed records.

The database was reportedly secured on June 8, roughly a week after the researchers made their disclosure.

According to reporting cited in connection with the incident, Singapore Airlines’ security team became involved in the remediation process and said it had engaged the relevant parties and taken measures to contain the problem.

- Advertisement -

That does not necessarily answer the most important question for affected travellers: whether someone else accessed the information before the researchers discovered it.

At this stage, there is reportedly no evidence showing that criminals obtained and exploited the archive. Researchers also found no indication that the database had appeared for sale on dark web marketplaces or that a hacking group had publicly claimed responsibility.

But the absence of evidence is not the same as proof that nobody else accessed the system.

A proper forensic investigation and detailed review of access logs would be needed to determine whether unauthorised parties reached the database before it was secured, or whether any information was copied.

That distinction matters because the exposed records could potentially support identity theft, convincing phishing campaigns and other forms of targeted fraud.

Misconfigured systems remain a major security problem

The incident also demonstrates why database misconfiguration continues to be one of the industry’s most persistent security risks.

Organisations increasingly depend on cloud infrastructure to store huge volumes of customer, employee and operational information. The technology can be secure, but mistakes involving authentication, access controls, network exposure or configuration can undermine those protections.

The problem becomes more difficult for large organisations operating complicated technology environments. Different teams may manage different cloud accounts, databases and applications, making it harder to maintain a complete picture of where sensitive information is stored and who can access it.

Security experts have repeatedly warned that organisations need stronger visibility across their technology infrastructure, regular configuration checks and independent security testing.

The airline incident is a particularly stark example because the exposed information was not simply commercial data. It involved records generated as part of international air travel and included information that can be closely associated with a person’s identity and journey.

For travellers, the immediate risk remains uncertain. The database has reportedly been locked down, and there is currently no confirmed evidence of criminal exploitation.

For businesses, however, the lesson is much clearer. A system does not need to be successfully hacked for a serious data breach to occur. A forgotten default password, an incorrect cloud configuration or an overlooked access route can be enough to expose millions of records.

Follow TechBSB For More Updates

- Advertisement -
Emily Parker
Emily Parker
Emily Parker is a seasoned tech consultant with a proven track record of delivering innovative solutions to clients across various industries. With a deep understanding of emerging technologies and their practical applications, Emily excels in guiding businesses through digital transformation initiatives. Her expertise lies in leveraging data analytics, cloud computing, and cybersecurity to optimize processes, drive efficiency, and enhance overall business performance. Known for her strategic vision and collaborative approach, Emily works closely with stakeholders to identify opportunities and implement tailored solutions that meet the unique needs of each organization. As a trusted advisor, she is committed to staying ahead of industry trends and empowering clients to embrace technological advancements for sustainable growth.

Read More

Trending Now