← Latest briefing

Technology

Misconfigured database exposes 220 million traveler records linked to Vietnam

Slashdot reports that an unsecured passenger database exposed over 220 million records spanning 2017 to 2026.

The short version

  • A misconfigured server linked to Vietnam exposed more than 220 million passenger and crew records spanning 2017 to 2026.[Slashdot]
  • Kinryu Labs discovered the exposed database during ransomware research on June 3.[Slashdot]
  • The affected system was secured following disclosure, but it remains unknown if third parties copied or misused the data.[Slashdot]

Key facts

  • A misconfigured Advance Passenger Information System database exposed over 220 million traveler and crew records spanning from 2017 to 2026.[Slashdot]
  • Kinryu Labs located the 107 GB Elasticsearch cluster named 'pax-info' on June 3 during ransomware research.[Slashdot]
  • The server was hosted within Viettel-assigned IP address space located in Hanoi.[Slashdot]

What remains uncertain

  • It is not known which specific Vietnamese organization was operating the exposed database.[Slashdot]
  • It remains unverified whether unauthorized entities accessed, copied, or abused the exposed travel data prior to its securing.[Slashdot]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.