Massive APIS Data Breach Exposes Over 220 Million Flight Passengers' Personal Details
A security research team has uncovered a staggering leak of more than 220 million traveler and crew records from an Advance Passenger Information System (APIS) that is linked to Vietnam, raising concerns about the protection of personal data in the global aviation ecosystem.
The exposed dataset spans a ten‑year window from 2017 through 2026 and contains a range of personally identifiable information, including full names, passport numbers, dates of birth, nationalities and detailed flight itineraries. Both passengers and airline crew members are represented in the files, indicating that the breach encompasses a broad cross‑section of individuals who have used commercial air services over the period.
Researchers say they accessed the database after discovering an unsecured endpoint that allowed unauthenticated queries. The APIS platform, which is routinely used by governments and airlines to exchange passenger data for border‑control and security screening, is typically protected by strict access controls. In this case, however, the Vietnam‑associated node appeared to lack adequate authentication, enabling the team to retrieve the records in bulk.
While authorities have not yet issued an official statement, the leak mirrors previous incidents where aviation‑related data stores were left vulnerable, underscoring a persistent gap in cybersecurity practices across the sector. Experts warn that the combination of passport details and travel histories could be exploited for identity theft, targeted phishing attacks, or more sophisticated surveillance operations, especially if the information is sold on underground forums.
In the wake of the discovery, cybersecurity analysts are urging airlines, governments and data‑handling agencies to conduct immediate audits of their APIS implementations and to enforce stronger encryption and authentication measures. Travelers are advised to monitor credit reports and remain vigilant for suspicious communications that reference their travel history. The incident is expected to trigger formal investigations in multiple jurisdictions as regulators seek to determine the breach’s scope and to reinforce safeguards against future exposures.
Comments (0)
Be the first to comment.
Join the discussion