A misconfigured cloud database left nine years of airline travel records sitting open on the internet.
Security researchers at Kinryu Labs found an Elasticsearch cluster hosted in Hanoi, Vietnam, that was technically walled off from the open internet but reachable through a cloud-based side door - and once inside, the cluster accepted default login credentials. The archive held 29 indices totaling roughly 107GB, generated by an Advance Passenger Information System that airlines use to report traveler data to border authorities. Two indices dwarfed the rest: 210 million passenger records and 10.5 million crew records, dated between January 2017 and April 2026, covering names, birth dates, passport numbers, seat assignments, and baggage references for people who passed through Vietnam on airlines across Asia-Pacific, Europe, and the Middle East. Researchers could not identify who owned the database, so they alerted Vietnamese authorities and the affected airlines on June 3; the archive was locked down five days later, with Singapore Airlines' security team leading the response.
This wasn't a hack - it was a door left unlocked for nine years. The scale means anyone who flew through Vietnam since 2017, on any of dozens of carriers, may have had passport and travel details sitting exposed, with no way to confirm who found it first without a full forensic audit that hasn't happened.
No evidence has surfaced of the data being sold or used anywhere, which is the one bit of good news here. But "no evidence yet" is doing a lot of work in that sentence - this is the same misconfigured-cloud-database story that exposed 670 million records at Infutor and three billion at IDMerit earlier this year, just with passports and boarding passes instead of credit histories.