Massive data breach sees 220 million traveler records exposed — nine years of airline info leaked including passenger and passport details
A series of misconfigurations allowed researchers to access a treasure trove of sensitive data - the archive has since been locked down.
A massive data breach has exposed the sensitive information of 220 million travelers, including airline records from 2017 to 2026. Kinryū Labs discovered misconfigured API databases in Vietnam that stored traveler records, which included personal details, travel information, seat assignments, and baggage references. The archive contained passenger and crew records, with two of the indices being particularly large - one with 210,318,069 passenger records and another with 10,465,631 crew records.
Travelers from Canada, China, Korea, and New Zealand were among those whose information was exposed. The database, which was hosted in Viettel-assigned IP space in Hanoi, Vietnam, was not limited to a specific airline, but included various airlines in Asia-Pacific, Europe, and the Middle East. Kinryū Labs reported the archive to Vietnamese authorities, airlines, and the country's CERT on June 3, 2026, and the database was locked down a week later on June 8.
At this time, there is no evidence of the archive being sold on the dark web or used by threat actors for identity theft, wire fraud, or other scams. Misconfigured databases remain a significant cause of data leaks, with businesses often failing to maintain proper visibility and security of their cloud-stored data.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.