220 million traveler records exposed in Vietnam-linked APIS leak
A misconfigured Advance Passenger Information System database linked to Vietnam exposed roughly 220 million passenger and crew records, including passport numbers, dates of birth, nationalities, and flight details covering nearly a decade. Researchers reached the cloud-hosted system using default credentials, suggesting basic security controls were never changed.
Why this matters: Passport numbers and travel histories are not the kind of data people can reset after a breach. This is identity and movement data covering hundreds of millions of people across nearly ten years of flights. It was left open with default credentials — the most avoidable failure in security. Governments collect APIS data because they say it keeps borders safe. The cost of that collection falls on travelers whose records now sit somewhere they did not choose. Who is responsible for protecting it matters, and right now that is not clear.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.