THE TELL

220 million passport records, one password nobody changed

A database of flight records — names, dates of birth, passport numbers — sat reachable online. Researchers proved it was real by finding their own trips inside it.

If you flew to, from or through Vietnam at any point since January 2017, your name, date of birth, passport number and the seat you sat in may have been sitting in a database that anyone with the right path could open. Not stolen in a dramatic hack. Just left reachable, with the factory password still on it.

The count is 220,783,700 records: 210,318,069 for passengers and 10,465,631 for crew, spanning January 2017 to April 2026. Security firm Kinryū Labs found the cluster on June 3 while looking at exposed databases as part of research into ransomware. It was named 'pax-info', held 29 indices and about 107 GB, and sat in Viettel-assigned IP space in Hanoi. The system appears linked to a Vietnamese organization; BleepingComputer could not confirm which one operated it.

What it means

This is the boring kind of failure, and that is exactly why it matters. From the open internet the database politely refused you: HTTP 401, "Unauthorized." Locked door, nothing to see. But a second route through the cloud reached the same cluster, and that route accepted default credentials — the login it shipped with, the one somebody was supposed to change on day one. Two small oversights that meant nothing separately and everything together.

What was inside is the full identity kit: names, dates of birth, sex, nationality, passport or travel-document number, document expiry date, issuing country — plus flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references and actual flight times. That last part is not trivia. It is a nine-year map of who travelled where, with whom, and when.

You can change a password. You cannot change your date of birth, and reissuing a passport is not something you do because a stranger might have a copy of the number.
Share this

And here is the part that should bother people most. The door was shut on June 8, five days after the report. But nobody can say how long it was open. The internet-scanning platform FOFA first recorded the host and port in October 2022 and identified the service as a database in July 2023 — yet Kinryū Labs could not determine when the passenger data first became retrievable through that second path. Without server logs, they also could not tell whether anyone had copied it. They found no ransom notes and no sign of the data for sale. That is reassuring in the same way an empty street at night is reassuring: you see nothing, which is not the same as nothing happening.

Who it matters to

Anyone who has taken a cheap connecting flight through Hanoi or Ho Chi Minh City since 2017 — the backpacker year, the visa run, the layover you booked because it was $80 less. Sample records reviewed by BleepingComputer included Korean, Chinese, Canadian and New Zealand travellers, and the data covered airlines across Asia-Pacific, Europe and the Middle East. You did not have to choose Vietnam to be in there; transiting was enough. It also covers 10,465,631 crew records — the pilots and cabin crew who cross that airspace for a living and whose passport details are now in a file of unknown travel history. One caveat worth keeping: these are travel records, not unique people. Fly ten times, appear ten times. The number of humans is smaller than 220 million, and nobody has published how much smaller.

What's next

Kinryū Labs says it expects to publish additional technical findings on its blog later this week — that is the next concrete thing to watch, and it may narrow down how long the data was reachable. Beyond that: BleepingComputer contacted Vietnamese authorities well in advance of publication and received no response. Changi Airport Group said it investigated but declined to comment. Singapore Airlines' security team told the researchers on June 8 that it had "engaged the relevant parties" and "taken steps to contain the issue," and gave no further comment. No government has announced a notification process, and no deadline has been named.

One detail to hold on to

The researchers confirmed the data was genuine by looking themselves up — matching records against their own trips to Vietnam. That is the whole story in one image: the only people who checked whether their passport details were in there were the ones who found the file. Everyone else in those 220 million records still has no way to look.

Sources: BleepingComputer, "220 million traveler records exposed in Vietnam-linked APIS leak," by Ax Sharma, September 8, 2026 (exclusive, based on findings from Kinryū Labs)

Why we ran this8/10

Паспортные данные 220 миллионов перелётов — с именами, датами рождения и номерами документов — девять лет лежали в открытой базе, до которой хватило пароля по умолчанию, и никто не может сказать, кто их успел скачать.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: $50 to get your Instagram back — and the s… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X