220 Million Traveler Records Exposed Online
A massive database containing approximately 220.8 million passenger and crew travel records, including sensitive personal information and flight details, was discovered exposed online due to a series of security misconfigurations. Researchers from Kinryƫ Labs found the Elasticsearch cluster, linked to a Vietnamese organization, on June 3, 2026. The exposed data spanned from January 2017 to April 2026 and included names, passport numbers, birth dates, nationalities, and detailed flight itineraries. The database, which operated as an Advance Passenger Information System (APIS), is designed to collect and transmit traveler data to border authorities before flights depart. This system is crucial for security screening, immigration control, and counterterrorism efforts. The exposed information also contained sex, document expiration dates, issuing countries, airlines, departure and arrival airports, seat assignments, baggage references, and flight times. While the records represent travel entries rather than unique individuals, repeat travelers could appear multiple times, potentially creating detailed profiles. Access to the database was not direct from the public internet.