Exposed airline passenger database leaked 220 million records with passport data
Researchers found an exposed database holding more than 220 million airline passenger and crew records, including passport numbers and full flight itineraries, left reachable online. The data came from an Advance Passenger Information System, the kind airlines use to send traveler identity and passport details to border authorities, and it covered anyone who flew to, from, or through Vietnam between 2017 and 2026. Exposed fields included names, dates of birth, nationalities, passport numbers with issuing countries, and flight, seat, and baggage details. Researchers reached it by chaining misconfigurations and default credentials, and it was later secured, though whether the data was copied first is unknown because no access logs existed.
- Check
- Travelers who flew through the region should watch for identity theft and travel-themed phishing using real passport or itinerary details, and organizations holding traveler data should audit exposed databases and default credentials.
- Affected
- More than 220 million passenger and crew records with passport numbers, birth dates, nationalities, and flight itineraries were exposed; the data enables identity theft, document fraud, targeted phishing, and surveillance of travelers.
- Fix
- For organizations, inventory internet-facing databases, remove default credentials, require authentication and encryption on data stores, and enable access logging; aggregators of passport and travel data should treat exposure as high-impact risk.