SecuritySeptember 18, 20269 min read

What to Do After the APIS Airline Passenger Data Breach

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the APIS Airline Passenger Data Breach

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

If you flew to, from, or through Vietnam between January 2017 and April 2026, your passport number, full name, date of birth and nationality may sit in a database that was left open on the internet. It held 220.8 million records. Passport numbers cannot be changed easily, so the response is monitoring and hardening, not a password reset.

What Happened

Security research firm Kinryū Labs discovered an unsecured Elasticsearch cluster on June 3, 2026 while surveying exposed databases. The cluster held Advance Passenger Information System (APIS) data — the manifest information airlines are legally required to transmit to border authorities before an international flight departs.

Two principal indices accounted for the bulk of it:

  • 210,318,069 passenger records
  • 10,465,631 crew records
  • 220,783,700 entries in total, spanning January 2017 through April 2026

The cluster was hosted in Viettel-assigned IP space in Hanoi and was reachable through a chain of misconfigurations; once reached, it accepted default credentials. Researchers notified Vietnamese authorities, the airlines represented in the data, and national CERTs starting June 3, and access was remediated on June 8, 2026. The findings were published publicly on September 8, 2026. No organization has publicly claimed ownership of the database.

Why Passport Data Is Different

A leaked password takes two minutes to rotate. A passport number is attached to you for up to ten years, appears on visa applications, hotel check-ins and bank onboarding forms, and is accepted as an identity proof by institutions worldwide. Nobody has confirmed whether this data was copied before it was secured — and with an open cluster, absence of proof is not proof of absence.

What Was Exposed

The records contained, for each passenger or crew member:

  • Full name
  • Date of birth
  • Sex
  • Nationality
  • Passport or travel-document number
  • Document expiration date and issuing country
  • Associated flight details

Payment card data and passwords were not part of the APIS record format. That is small comfort: name, date of birth, nationality and passport number together are a complete identity package for account-opening fraud, visa fraud, and highly convincing targeted phishing.

Am I Affected?

There is no notification process here. This was an exposed database with no confirmed operator, not a company breach with a legal duty to write to you — so no letter is coming. Assume exposure if all of these are true:

  • You took an international flight to, from, or transiting through Vietnam
  • The flight was between January 2017 and April 2026
  • You travelled on a passport, as a passenger or as aircrew

Nationality is not a filter. APIS records cover every traveller on a covered flight regardless of citizenship, so travellers from the US, UK, EU, Australia, Korea, Japan and elsewhere are all potentially in the file.

Step 1: Check Whether Your Passport Is Still Valid

Dig out the passport you used for those flights. If it has already expired, the leaked number has far less value — expired document numbers fail most verification checks. If it is still valid, treat the number as compromised and continue through the remaining steps.

Step 2: Report It to Your Passport Authority

You generally cannot get a replacement passport just because a number appeared in a leak, but reporting creates a record you can point to later if the document is misused.

  • United States: Contact the State Department's National Passport Information Center at 1-877-487-2778. Report a lost or stolen passport only if it genuinely is — a false report invalidates a document you still hold.
  • United Kingdom: HM Passport Office, via GOV.UK.
  • EU and elsewhere: Your national passport issuing authority or foreign ministry.

If you were already planning to renew, bring it forward. A new passport means a new number, which retires the leaked one.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 3: Freeze Your Credit

Name plus date of birth plus a government ID number is the standard input for opening fraudulent accounts. A credit freeze is free, lasts until you lift it, and blocks new-account fraud at the source:

  • Equifax: equifax.com/personal/credit-report-services
  • Experian: experian.com/freeze
  • TransUnion: transunion.com/credit-freeze

Freeze all three. A freeze at one bureau does nothing about an application checked against another.

Step 4: Expect Targeted Travel Phishing

The most likely near-term use of this data is not fraud — it is pretexting. A message that correctly cites your full name, date of birth, passport number and a real flight you took is extraordinarily convincing.

  • Treat any unexpected message about visas, immigration status, flight compensation or "verifying your travel document" as hostile until proven otherwise
  • Never confirm or supply passport details in reply to an inbound email, SMS or call
  • Contact airlines and immigration authorities only through numbers and addresses you look up independently
  • Be sceptical of fee demands — no legitimate authority collects visa or immigration fees by gift card, crypto, or bank transfer to a personal account

Airline Loyalty Accounts Too

Passport number and date of birth are common verification answers for frequent-flyer account recovery. Change the password on every airline loyalty account, turn on two-factor authentication, and check your points balance — miles are liquid and are stolen routinely.

Step 5: Watch for Identity Misuse

  • Pull all three credit reports free at annualcreditreport.com and look for accounts and inquiries you do not recognise
  • Check your IRS account for a filed return you did not submit, before tax season rather than during it
  • Review bank and card statements monthly instead of glancing at the balance
  • If something surfaces, file at identitytheft.gov — the FTC report is what banks and bureaus ask for

Step 6: Shrink the Rest of Your Footprint

A passport number on its own has limited use. Combined with a current home address, phone number and a list of your relatives — all of which people-search sites publish for free — it becomes a working identity kit. This is the part of your exposure you can still control.

PrivacyOn removes your personal information from 100+ data broker and people-search sites, re-submits automatically when listings reappear, and runs dark web monitoring so you get alerted if your details show up in breach dumps or on criminal marketplaces. Family plans cover up to 5 people and plans start at $8.33/month.

Start with a free scan to see what a scammer holding your passport number could pair it with today. See PrivacyOn plans.

Frequently Asked Questions

Was my passport number leaked in the APIS database exposure?

If you flew to, from, or through Vietnam on any international flight between January 2017 and April 2026, assume yes. The database held 220.8 million passenger and crew records covering that entire period, and APIS manifests include every traveller on a covered flight regardless of nationality. There is no lookup tool and no notification list, because no organisation has claimed the database.

Do I need to replace my passport?

Not automatically. Most passport authorities will not reissue a document solely because its number appeared in a leak, and falsely reporting a valid passport as stolen invalidates a document you still need. If your passport is close to renewal, renew early so you get a new number. If it has already expired, the leaked number has little residual value.

Can someone travel on my leaked passport number?

Not on the number alone. Border control checks the physical document, its chip, and its biometrics against the holder, so a number without a document does not board a plane. The realistic risks are document-number fraud in online visa and identity-verification flows, and phishing that uses the accurate details to establish credibility.

Who was responsible for the exposed database?

Unknown. The cluster sat in Viettel-assigned IP space in Hanoi, but BleepingComputer could not confirm which Vietnamese organisation operated it, and none has come forward. Access was remediated on June 8, 2026, five days after Kinryū Labs reported it. Whether anyone copied the data before then has not been established.

Will I get a breach notification letter about this?

Almost certainly not. Breach notification laws obligate an identified controller of the data. With no organisation acknowledging ownership, there is nobody under a duty to write to affected travellers — which is exactly why acting on your own initiative matters more here than in a normal corporate breach.

What should I do first if I think I am affected?

Freeze your credit at all three bureaus, since it is free and blocks the highest-consequence outcome. Then change passwords and enable two-factor authentication on your airline loyalty accounts, where passport number and date of birth are common recovery answers. Then reduce what else is publicly linkable to your name — a free PrivacyOn scan shows which brokers are publishing your address and phone alongside it.

How long will this data stay dangerous?

Until the passports expire. Records ran to April 2026, and passports are typically issued for five to ten years, so a substantial share of the leaked documents remain valid for years. Leaked identity data also circulates indefinitely once copied, which is why continuous dark web monitoring is more useful here than a one-time check.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families