220 million traveler records exposed in Vietnam-linked APIS leak
AI Summary
An Elasticsearch cluster named 'pax-info', linked to a Vietnamese organization and hosted in Viettel-assigned IP space, was found exposed online due to chained security misconfigurations. The database contained over 220 million traveler and crew records spanning from January 2017 to April 2026, including personally identifiable information such as names, passport details, flight data, and nationalities. The system was accessible via default credentials after initial HTTP 401 authentication was bypassed through a cloud-based path, and it was secured on June 8 following disclosure by Kinryū Labs. It remains unknown whether the data was accessed or exfiltrated by malicious actors prior to remediation.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| IP | not provided | Details → |