A Vietnam-linked APIS database reportedly exposed more than 220 million passenger and crew records. Passport, route, and timing data can make phishing feel personal.
BleepingComputer reported on September 8, 2026, that an Advance Passenger Information System database linked to Vietnam exposed more than 220 million passenger and crew records. The records spanned January 2017 through April 2026.
The exposed fields reportedly included names, dates of birth, nationalities, passport or travel-document numbers, document expiration dates, flight numbers, airports, seat assignments, baggage references, and timing details. Researchers said access was possible through chained cloud misconfigurations and default credentials, and that the issue was remediated in June.
Why it matters for verification
Travel records are identity records. Flight details, passport data, and route history can help attackers create convincing messages about visas, refunds, hotel bookings, delivery, roaming, or account verification.
BillioPlus checklist
- Do not trust travel-related SMS links just because they include real itinerary details.
- Use official airline, airport, or government portals to verify urgent travel messages.
- Protect passport scans and avoid sending them through casual chat threads.
- Review account recovery settings after major travel or identity-data incidents.
Source links
Tags
Chinedu Celestine Okpala
BillioPlus Team · Content & Guides
