Connect with us

NEWS

Vietnam APIS Passenger Files Sat Behind Default Credentials

A Vietnam-hosted APIS archive of 220.8 million travel records took default passwords, even though a 2011 decree ordered those passenger files kept secret.

Published

on

A Vietnam-hosted Advance Passenger Information archive of 220.8 million traveler records accepted default passwords after researchers found a second path in. Kinryū Labs reached the cluster on June 3, 2026. It was locked on June 8. Nobody has said they ran it.

The files cover passengers and crew who flew to, from, or through Vietnam from January 2017 through April 2026. Passports, seats, bags, and flight times sat in the same pile. The law that forced airlines to send that data already told agencies to keep it secret.

A Border Cluster That Took the Default Password

Kinryū Labs was not hunting a named airline. The group was scanning open databases while studying ransomware crews that wipe Elasticsearch and leave a note. On June 3 it found a cluster named pax-info, hosted in Viettel-assigned IP space in Hanoi. From the public internet the endpoint answered HTTP 401, which looks closed. A cloud path still reached the same cluster, and that path accepted default credentials.

THE PAX-INFO CLUSTER

  • The haul: About 107 GB across 29 indices, with two giant stores of passenger and crew rows.
  • The door: Direct web access failed with HTTP 401; a cloud path then took the default login.
  • The host: Viettel-assigned address space in Hanoi, with no named operator confirmed.
  • The check: Researchers matched rows against their own trips to Vietnam and treated the files as real.

Internet scanners had already seen the machine. FOFA first logged the host and port in October 2022 and tagged the service as a database in July 2023. Kinryū Labs could not say when the cloud path started handing out the passenger indices, so the life of the records (January 2017 through April 2026) is not the same as the life of the leak.

THE LOCKDOWN CALENDAR

  1. October 2022: FOFA records the host and port.
  2. July 2023: FOFA tags the service as a database.
  3. June 3, 2026: Kinryū Labs finds pax-info and alerts Vietnamese agencies, airlines in the files, and national CERTs.
  4. June 8, 2026: Access is cut, five days after the first report.
  5. September 8, 2026: The lab’s findings go public; a fuller technical note was still pending at that disclosure.

That five-day close is the part that worked. The part that did not is simpler. A feed built for border posts was sitting in a cluster class the same lab had already counted in a survey of exposed Elasticsearch hosts, the kind ransomware crews treat as easy prey.

210 Million Passenger Rows and 10.5 Million Crew Files

Two indices carried almost the whole archive. One held 210,318,069 passenger records. The other held 10,465,631 crew records. Combined they make 220,783,700 entries, the 220.8 million figure in the headline. Repeat travelers appear more than once, so the number is trips, not unique people.

WHAT THE TWO BIG INDICES HELD

Index Records Window
Passenger 210,318,069 January 2017 through April 2026
Crew 10,465,631 January 2017 through April 2026
Combined 220,783,700 Same span, 107 GB, 29 indices

Sample rows reviewed with the researchers included travelers from Korea, China, Canada, and New Zealand, among other countries. Airlines from Asia-Pacific, Europe, and the Middle East showed up in the same stores. Anyone who flew through Vietnam in that window could be in the pile, including crew.

FIELDS IN THE ARCHIVE

  • Identity: Names, dates of birth, sex, and nationality.
  • Travel papers: Passport or document numbers, expiry dates, and issuing countries.
  • The flight: Airline, flight number and date, plus departure, destination, and transit airports.
  • The cabin: Seat assignments, baggage tags, and scheduled, estimated, and actual times.

That last group is the tell. Classic API is a pre-arrival identity dump for immigration. Seats, bags, and actual wheels-up times are the extra grain that turns a border check into a searchable diary of who sat where, and with which suitcase tag, across nine years of traffic.

Vietnam’s 2011 Decree Already Ordered These Files Kept Secret

Airlines did not invent this pile for marketing. From June 1, 2011, carriers flying into Vietnam must send API data before landing, under Decree 27/2011/ND-CP, issued April 9, 2011. The packet covers the flight and the people on it: names, sex, date of birth, nationality, and the papers used to enter or leave. It goes to the airport authority on a 24/7 feed, then onward to the civil aviation body, immigration, border public security, and customs.

The same decree sets the use. API data is for aviation safety and security, political security, social order, and anti-smuggling work. Agencies must keep airline business figures and the personal details of passengers and crew secret. They must not pass the files to other bodies unless the airline that supplied them consents.

A nine-year Elasticsearch archive on default credentials is the opposite of that instruction. IATA’s own passenger-data note is blunt about why the files exist at all: API is not required for aircraft operator processes, so carriers collect it because a state told them to. The passenger never booked a product called pax-info. The state required a feed. Someone kept the feed.

Who Was Allowed to Hold the Feed

Decree 27 names the Vietnamese bodies allowed to receive, handle, and use API data: the Civil Aviation Administration and international airport authorities under the Ministry of Transport; immigration and border public-security offices under the Ministry of Public Security; and customs units under the Ministry of Finance. Kinryū Labs could not put pax-info on any of those doors. Viettel’s name in the record is an IP assignment, not a claim of ownership, and Viettel has not stepped forward as the operator.

The researchers told Vietnamese agencies, the airlines named in the indices, and national computer-emergency teams on June 3. Vietnamese agencies had not issued a public reply by the September 8 disclosure. Changi Airport Group, which runs Singapore’s Changi Airport, said it had looked into the matter and then declined to comment. Several large airlines appear in the files. There is no sign those carriers ran the cluster or that their own networks were broken into.

That gap is the live problem for anyone whose passport number is in the rows. A traveler can write to an airline. A traveler cannot write to an address in Hanoi that no one will claim. Vietnam’s Law on Protection of Personal Data (Law 91/2025/QH15) took effect January 1, 2026, months before the June report, and it tells controllers to notify the specialist agency within 72 hours of detecting a breach that can harm people or the state. With no named controller, that clock has nowhere obvious to start.

The 48-Hour Clock Against a Nine-Year Archive

API is a pre-arrival tool. Other governments that run the same class of system publish short clocks, then delete. U.S. Customs and Border Protection’s privacy assessment for APIS, updated February 2021, says CBP will retain APIS records for 13 months. The European Union’s API rulebook tells carriers and border agencies to delete API data 48 hours after receipt, with a narrow extra window if a passenger never shows at the border. Even passenger name records, a fatter booking file than API, come with an ICAO recommended cap of five years.

HOW LONG THE SAME KIND OF FILE IS SUPPOSED TO LAST

System What it holds Published clock
pax-info archive in Hanoi API-style passenger and crew rows, plus seats, bags, and times January 2017 through April 2026
U.S. CBP APIS Advance passenger information 13 months
EU API rules API held by carriers and border agencies 48 hours, then delete

Set those clocks next to pax-info and the archive stops looking like a border check that ran long. It looks like a dossier. Cassius Edison, chief operating officer at Closed Door Security, has described the wider habit behind spills like this: firms no longer see their full IT estate, so audits miss the copy that should never have been kept. A 24/7 inbound feed is one job. A searchable nine-year index is another job, and it is the one the 2011 decree did not describe.

Singapore Airlines Locked a System It Did Not Run

On June 8, Singapore Airlines’ security team mailed Kinryū Labs to say the hole was being closed. The carrier is in the files. It is not, on the evidence released so far, the owner of the cluster. It still did the janitor work.

engaged the relevant parties and have taken steps to contain the issue.

Singapore Airlines security team, email to Kinryū Labs, June 8, 2026

That sentence is the whole public remediation record. The lab found no ransom note on the cluster and no strange extra index that would hint a crew had already moved in. It also could not see server logs, so it cannot say whether anyone else used the cloud path before June 3. Singapore Airlines gave no further comment after that mail. The unnamed operator, if there is still one, has said nothing at all.

For a carrier, this is a familiar bind. The state demands the API packet at boarding. The packet then lives on someone else’s machine. When that machine is open, the airline whose passengers are in the rows is the party people can actually phone. SQ got the call, and it shut a door on a house it does not appear to own.

The Copy That Logs Cannot Rule Out

A crime-forum listing would be a loud signal. Kinryū Labs said it could not find this dataset for sale, and no group has claimed a theft. That is worth reporting. It is not a forensic finding. Default logins are quiet. Anyone who found the same cloud path in 2023, or in 2025, could have copied 107 GB, kept the files, and never advertised the haul. Without logs, the clean market is compatible with a private copy.

WHAT WE KNOW

  • The contents: 220,783,700 passenger and crew records, passports included, dated January 2017 through April 2026.
  • The path: HTTP 401 on the open net, default login on a cloud route, host in Viettel IP space in Hanoi.
  • The close: Reported June 3, 2026, locked June 8, with Singapore Airlines helping to round up the parties.

WHAT IS UNCONFIRMED

  • The owner: No Vietnamese body or vendor has claimed pax-info.
  • The first open date: FOFA saw the host in October 2022; the cloud path’s start date is unknown.
  • The copy: No sale is on view, and no log review has ruled one out.

Kinryū Labs said at the September 8 disclosure that more technical notes would follow. Until someone names the operator, the people in those rows are holding a known leak with no named desk to ask whether their passport number left the cluster. The feed that was supposed to meet a flight had already outlived the flight by years.

Harry is the editor of WORLDHAB, an independent publication that he owns and edits himself. His decade in journalism started in reporting and moved into editing, and it left him with a short list of promises that readers can expect every article here to keep. Sources are named and linked, so a claim about a company, a government or a team can be traced to the statement, filing or transcript it came from. Dates are given in full, figures are checked against the original table before publication, and where a number is an estimate the story says whose estimate it is. Headlines describe what happened rather than tease it. Those expectations hold across all ten sections WORLDHAB publishes for an international audience: news, business, technology and science on one side, sports, entertainment, lifestyle and travel on another, with auto and gaming covered with the same seriousness. Harry keeps a public corrections policy and marks every change on the article it affects. Reader mail is read by him and answered from support@worldhab.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending