Massive Data Leak Exposes Vietnam Aviation Records
One of the most sensitive aviation databases proved to be guarded less securely than a rudimentary web service. On June 3, Kinryū Labs uncovered a staggering 220,783,700 records concerning passengers and flight crews within an Elasticsearch cluster linked to Vietnam. This massive repository harbored highly sensitive passport details, flight itineraries, seating assignments, and registered luggage linkages. Alarmingly, the database remained active and continued to ingest fresh information during the discovery.
Unpacking the Exposed Passenger Data
The compromised cluster, designated “pax-info,” contained twenty-nine distinct indices, encompassing approximately 107 gigabytes of data. Passengers accounted for 210,318,069 records, while crew members comprised the remaining 10,465,631 entries. It is important to note that the figure of 220.8 million does not equate to the total number of unique individuals affected, as a single frequent traveler could appear numerous times within the database. The records spanned a substantial timeframe, from January 7, 2017, through April 30, 2026, and involved an astonishing 1,008 different airlines.
Every individual record meticulously linked a person’s name, date of birth, gender, nationality, passport number, and expiration date to a specific flight itinerary. This included the departure, transit, and destination airports, alongside the flight number, seat assignment, and luggage tags. The tracking system comprehensively monitored transit passengers as well.
Bypassing Authentication Mechanisms
While a direct query to the server appropriately returned an HTTP 401 unauthorized error, an alternative pathway to the cluster remained entirely exposed from within the cloud environment. According to researchers detailing the Vietnam passenger APIs exposure, after navigating this bypass, the system astonishingly accepted unmodified default credentials. Furthermore, the interface permitted the effortless extraction of records into JSON format with a single action. Similar catastrophic failures involving exposed online databases have previously precipitated massive, automated attacks against MongoDB instances.
A crucial technical caveat requires mention. Kinryū Labs designates the credentials as “factory defaults,” yet they decline to disclose them publicly. Conversely, official documentation explaining how to set up Elasticsearch security indicates that in version 8.x, the superuser password is automatically generated during the initial startup. Therefore, based solely on open-source intelligence, it remains impossible to definitively ascertain whether these credentials were an intrinsic Elasticsearch default or a flawed component of the specific operator’s configuration.
Tracing the Source of the Leak
The compromised host resided within the Viettel address space located in Hanoi; however, the ultimate owner of the database remains unidentified. Data concerning VietJet Air and Vietnam Airlines dominated the repository, yet hundreds of international carriers, including Aeroflot and Belavia, were also present. This overarching context bears a striking resemblance to the ongoing Sirena-Travel case, wherein a Russian court is currently investigating the potential illicit acquisition of airline passenger data via stolen credentials.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.