Skip to content
Breaking:

Cloud Database Misconfiguration Exposes 220 Million Airline Traveler Records

A misconfigured Elasticsearch cluster hosted in Vietnam left nine years of sensitive flight and border control data publicly accessible.

By The Company Wire4 min read
Share
Kinryū Labs — Cloud Database Misconfiguration Exposes 220 Million Airline Traveler Records
Kinryū Labs — Cloud Database Misconfiguration Exposes 220 Million Airline Traveler Records. Photo: TechRadar Pro.

A cloud security misconfiguration left more than 220 million passenger and airline crew records exposed online for an undetermined period, exposing passport information, flight itineraries, and personal details spanning a nine-year timeframe, as first reported by TechRadar Pro.

Cybersecurity researchers at Kinryū Labs initially uncovered the unencrypted 107-gigabyte Elasticsearch cluster in early June 2026. While the database was shielded from standard public internet scans, it remained reachable through an alternative cloud-hosted network path and operated using default administrative credentials. The repository comprised 29 separate indices containing data generated by an Advance Passenger Information System (APIS)—a standard platform used by commercial airlines to transmit passenger and crew details to national border agencies prior to flight departures and arrivals.

The vast majority of the leaked data was contained within two primary indices: one holding 210,318,069 passenger entries and another containing 10,465,631 crew records created between January 2017 and April 2026. The exposed fields extended beyond basic names, birth dates, nationalities, and passport details to include gender, document expiration dates, issuing authorities, flight routing, destination airports, seat numbers, and baggage tracking numbers. Because APIS logs record individual travel events rather than unique individuals, frequent flyers were logged multiple times within the repository. Affected travelers included citizens of Canada, China, South Korea, and New Zealand flying across numerous carriers throughout Europe, the Middle East, and the Asia-Pacific region.

The exact administrator of the database remains unidentified, though network routing traces mapped the cluster to IP addresses assigned to Vietnamese telecommunications operator Viettel in Hanoi. Because the infrastructure owner could not be determined directly, Kinryū Labs submitted disclosure reports on June 3 to Vietnamese state authorities, regional air carriers, and the country's Computer Emergency Response Team. The database was rendered private on June 8, with Singapore Airlines' internal security operations team leading containment efforts and coordinating remediation across affected parties.

Security analysts emphasized that without access to system transaction logs and a full forensic assessment, it is impossible to verify whether malicious actors accessed or exfiltrated the database prior to its discovery. However, security monitoring has not identified any dark web marketplaces or hacker forums offering the repository for sale or claiming responsibility for an exfiltration.

The exposure highlights persistent operational vulnerabilities surrounding enterprise cloud deployments and identity management. Cassius Edison, chief operating officer at Closed Door Security, noted that the expanding footprint of modern corporate IT environments makes system misconfigurations a recurring hazard. Edison stated that many organizations struggle with visibility across distributed infrastructure and recommended regular independent security audits and penetration testing to identify unmanaged assets.

The incident follows several other high-volume database exposures reported earlier in 2026. Consumer identity platform Infutor exposed over 670 million consumer identity records due to security misconfigurations, while identity verification firm IDMerit inadvertently left more than three billion records open to the web via an unsecured MongoDB instance.

Sources

  1. TechRadar Pro

Company: Kinryū Labs

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.