220M Passport Records Exposed in Vietnam APIS Leak
An exposed Vietnam-linked APIS database held 220 million traveler records: names, passport numbers, birth dates, nationalities, and flight routes.

Governments have spent thirty years building systems that demand more passenger data from airlines, each iteration more detailed than the last, and the security of the databases holding that data has not kept pace with the appetite for collecting it. BleepingComputer’s Monday exclusive is the latest example: an exposed database tied to Vietnam’s Advance Passenger Information System held 220 million passenger and crew records.
The leaked fields are names, passport numbers, dates of birth, nationalities, and flight route data. Passport numbers are the piece that matters most. You cannot cancel a passport the way you cancel a credit card; correcting this exposure requires a consulate visit, a fee, and waiting on government processing time. When a passport number appears alongside a full name, birth date, and travel history, the resulting dossier is useful for identity fraud, synthetic-identity creation, and targeted phishing built on real movement patterns.
APIS databases are designed to carry pre-arrival passenger manifests transmitted by airlines to border and customs agencies before a flight lands. The premise of the system is that aggregating this data in advance improves screening. The recurring problem with that premise is that “aggregating data” and “securing data” are different operations, and the agencies operating these systems consistently treat the first as the mission and the second as an IT problem.
At 220 million records, the scope here is large even by the standards of a bad year. IDScan’s breach earlier this month covered 153 million driver license records; the Manchester Airports Group breach in August exposed 8.7 million travelers. The pattern in aviation and travel infrastructure is consistent enough to stop calling it a coincidence.
BleepingComputer characterizes the database as “Vietnam-linked” without specifying which entity operated it or how the exposure occurred. Whether this is a misconfigured cloud instance, an unsecured API endpoint, or something else will matter for remediation; it does not change what was exposed.
For anyone who has traveled through Vietnamese airports: there is no patch for a leaked passport number. Monitoring accounts for unusual activity and staying alert to phishing attempts that reference travel history are the practical near-term steps. The agencies that demanded this data in the first place owe affected travelers a clearer explanation than “Vietnam-linked” eventually provides.
Found this useful? Share it.


