Your passport in a leaky database: the APIS breach explained
220 million airline passenger records—including passport numbers and flight histories—were left exposed online. Here is what happened and what it means for travellers.
Every time you board an international flight, the airline transmits a package of personal data to border authorities before the aircraft pushes back from the gate. Your name, passport number, date of birth, nationality, seat assignment, and flight number all travel ahead of you, invisibly, through a system called Advanced Passenger Information—APIS. It is a legal requirement in most countries, and you have no option to decline it.
On 3 June 2026, security researchers at Kinryū Labs discovered that a vast collection of exactly this kind of data had been sitting on the open internet, protected by nothing more than default credentials. The database contained 220,783,700 passenger and crew records covering almost a decade of international travel. This article explains what happened, what is in the exposed data, and why passengers should take this kind of exposure seriously even if they never hear their own name mentioned in a breach notification.
There is no product that can un-ring this bell. But understanding what was leaked—and how it got there—is the starting point for making better decisions about your privacy going forward.
What is APIS and why does it exist?
APIS is a pre-departure data-sharing requirement that originated in the United States after the September 2001 attacks and has since been adopted, in various forms, by governments across the world. Airlines are legally obligated to transmit passenger manifests to border and immigration agencies before each international departure. The data typically includes:
- Full name as it appears on the travel document
- Passport or travel document number
- Document type, issuing country, and expiry date
- Date of birth and nationality
- Flight number and itinerary details
- Seat assignment
The system exists to allow authorities to screen passengers against watchlists before a flight lands, rather than after. From a border security perspective, the rationale is straightforward. From a privacy perspective, it means every international traveller has already handed over their most sensitive identity documents to multiple government databases—and, as this incident shows, to whoever processes and stores that data on the airlines' behalf.
What Kinryū Labs found
Researchers at Kinryū Labs identified an exposed Elasticsearch cluster on 3 June 2026. The cluster, labelled pax-info, was hosted on IP addresses assigned to Viettel—Vietnam's state-owned telecommunications operator—in Hanoi. It was reachable from the open internet and accessible using only default credentials, meaning no sophisticated attack was required to read its contents.
The scale of the exposure was significant. The database held records for travel to, from, or through Vietnam spanning January 2017 to April 2026—more than nine years of passenger data. Carriers from across Asia-Pacific, Europe, and the Middle East were represented, which means the nationalities of affected passengers extend well beyond Vietnamese citizens.
BleepingComputer broke the story on 8 September 2026. Access to the cluster was closed on 8 June 2026—five days after the initial discovery. As of the time of writing, no organisation has publicly claimed ownership of the database. Whether the data was exfiltrated during the window it was exposed remains unknown.
Why default credentials on a database this size are so damaging
A common assumption is that a misconfiguration—as opposed to a targeted hack—is somehow less serious. That assumption does not hold. A misconfiguration of this kind means the data was accessible to anyone who knew to look for it, including automated scanners that continuously probe the internet for exactly these kinds of open systems.
Elasticsearch clusters have appeared in major data exposures before precisely because the software, by default, does not require authentication. A database administrator who deploys a cluster without changing that default, or without placing it behind a firewall, may not realise it is reachable from outside the organisation until a researcher—or a malicious actor—points it out.
The chained misconfigurations described by Kinryū Labs suggest this was not a single oversight but a sequence of them: the cluster was publicly accessible, authentication was not enforced, and the data was not encrypted at rest in a way that would have made the exposure meaningless. Each of those failures would need to have been caught independently, and none was.
What makes passport data particularly sensitive
Financial data gets the most attention in breach reporting because the harm is often immediate and measurable. Passport data is different. It is more durable and, in some ways, more dangerous.
Your passport number does not change until your passport expires—typically every ten years. Your date of birth and nationality never change. A combination of these fields, cross-referenced with your name and travel history, is enough to build a convincing identity profile. That profile can be used to:
- Open fraudulent financial accounts in jurisdictions with weaker verification
- Construct synthetic identities that blend real and fabricated information
- Target phishing campaigns with highly specific, credible personal details
- Facilitate visa fraud or border crossing under a stolen identity
Flight histories add another layer. Knowing where a person has travelled, when, and in which seat creates a behavioural profile that can be used in social engineering—a fraudster who knows you flew from London to Ho Chi Minh City in March 2023 has a much more convincing opening to a targeted scam than one working from a name and email address alone.
The specific problem with mandatory data collection
What makes APIS breaches distinct from, say, a retailer leaking customer emails is that the data was not collected voluntarily in any meaningful sense. You cannot opt out of APIS submission and still board an international flight. The data is extracted from your passport at check-in and transmitted on your behalf without any ongoing consent mechanism.
This creates a structural problem: travellers bear the privacy risk of data collection they had no choice but to permit, while the organisations responsible for storing and transmitting that data—airlines, ground handlers, government agencies, and their contractors—face consequences that rarely match the severity of the exposure.
The APIS breach is a clear example. The database covered records from dozens of carriers across multiple continents. The passengers whose data it contained are unlikely to receive individual breach notifications, may never know their records were exposed, and have no practical remedy even if they do find out.
What you can and cannot do as a traveller
It is worth being direct: there is no way to prevent your APIS data from being collected. If you fly internationally, it is submitted. Full stop. The practical question is what you can do to limit broader privacy exposure and reduce the value of your data to anyone who might obtain it.
On your travel devices
Public Wi-Fi at airports, hotels, and transport hubs is a separate risk surface from the APIS database itself, but a real one. When you connect to an untrusted network, your DNS queries, metadata, and unencrypted traffic are visible to whoever controls that network. Using a VPN on your devices while travelling encrypts that traffic and prevents passive interception. PremierVPN's travel VPN is designed for exactly this kind of use, including support for networks in countries with restrictive filtering. If you are travelling somewhere with heavy internet censorship, the PremierVPN X client for Windows and PremierVPN X for macOS use the VLESS+REALITY protocol, which is specifically designed to be resistant to deep packet inspection.
On your accounts and identity documents
If your passport number has been exposed in a breach, renewing your passport when it next comes up for renewal will change that number—a small but genuine step. In the meantime, monitor your financial accounts and credit report for unusual activity. Be sceptical of any communication that references your travel history, even if the detail sounds implausibly specific; that specificity is a warning sign, not a reason to trust the source.
On your broader digital footprint
The value of any single breach depends partly on what other data it can be combined with. Minimising the amount of personal information you share across services—particularly the kind that is persistent, like your date of birth and home address—reduces the richness of any profile an attacker can build. PremierVPN's free browser extension, PremierVPN Protect, blocks trackers and some ad-network fingerprinting at the browser level, which is one small way to reduce how much of your online behaviour is recorded and potentially correlated.
The unanswered questions
Several things about this breach remain unclear and may never be fully resolved. No organisation has come forward to claim ownership of the pax-info cluster. That ambiguity matters because it affects who is legally responsible for notifying affected passengers and what regulatory action, if any, can be taken.
The five-day window between discovery (3 June) and closure (8 June) is also significant. That is enough time for automated scrapers to have copied substantial portions of the database. The absence of evidence that the data was exfiltrated is not the same as evidence it was not, and the distinction matters when assessing ongoing risk.
Finally, the geographic scope—carriers from Asia-Pacific, Europe, and the Middle East—means data protection authorities in multiple jurisdictions may have grounds to investigate. Whether they do, and what leverage they have over a database whose owner has not identified themselves, is another open question.
What this means in practice
The APIS breach is an example of a category of risk that travellers rarely think about: data collected as a condition of doing something ordinary, stored by parties you never interact with directly, and exposed through negligence rather than targeted attack. It does not require any action on your part to be affected.
The practical takeaway is not to stop flying, which would be an absurd overreaction, but to think carefully about where your data ends up when you hand it over—and to protect the parts of your digital life that you do control. That means strong authentication on financial accounts, a sceptical approach to unsolicited contact that references your personal details, and using a VPN when connecting to networks you do not own.
If you are a frequent international traveller and want to understand how PremierVPN handles your data by contrast, our no-logs policy is published in full. The principle is simple: data that is never collected cannot be leaked.
Share this article
Protect your privacy with PremierVPN
Fast, secure, and truly private VPN service with servers in 12+ countries.
Get Started