220 million traveler records exposed in Vietnam-linked APIS leak
Summary
An exposed Advance Passenger Information System (APIS) database linked to Vietnam has leaked 220 million traveler and crew records. The exposed data includes names, passport numbers, dates of birth, nationalities, and flight details from 2017 to 2026. Researchers gained access to the database via a cloud path using default credentials.
IFF Assessment
The exposure of such a large volume of sensitive traveler data is a significant win for threat actors who can use this information for identity theft, phishing attacks, and other malicious activities.
Defender Context
This incident highlights the critical need for robust access controls and secure credential management, especially for systems handling vast amounts of personally identifiable information. Defenders should prioritize regular audits of cloud configurations and employ strong authentication mechanisms to prevent unauthorized access.