Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet
A misconfigured Elasticsearc 2026-9-8 14:56:53 Author: thecyberexpress.com(查看原文) 阅读量:1 收藏

Airline, Data Leak,

A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed.

The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment – the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the server to IP address space assigned to Vietnamese telecommunications operator Viettel in Hanoi but said they could not confirm which organization operated it.

What was exposed

As per BleepingComputer, the data set combined identity documents with granular travel history. Exposed fields included names, dates of birth, sex and nationality; passport or travel document numbers, expiration dates and issuing countries; and flight numbers and dates, airline names, departure, destination and transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times.

That combination is unusually sensitive. Passport numbers are difficult to change and useful for identity fraud and account takeover at travel providers, while the itinerary fields – particularly transit airports and actual flight times – allow reconstruction of an individual’s movements over nine years. Security researchers have long flagged APIS-style data as a surveillance risk precisely because it maps people to places at fixed times.

Also read: Why Airline Data Breaches Matter – And Why Qantas Could Have Been Worse

Two misconfigurations

According to Kinryu Labs, the cluster was protected inconsistently. Direct access over the internet returned an HTTP 401 authentication error, which would give a casual scanner the impression the system was locked down. An alternative cloud-based access path, however, reached the same cluster and accepted default credentials.

The exposure appears to have been long-lived. Internet scanning service FOFA detected the host in 2022 and identified it as a database in 2023. Kinryu Labs reported the issue on June 3, 2026, and the cluster was secured by June 8. Singapore Airlines assisted in coordinating the response, the researchers said. There is no indication any airline was itself breached or operated the server.

Researchers said they found no evidence the data was stolen, but noted that without server logs they could not determine whether anyone copied it during the years it was reachable — a distinction that matters more than it may appear, because notification obligations in several jurisdictions turn on whether unauthorized access can be ruled out.

Compliance exposure

Vietnam’s Personal Data Protection Law, Law No. 91/2025/QH15, took effect Jan. 1, 2026 – before the exposure was reported and remediated. The statute requires notification within 72 hours of detecting a violation, rather than from the time it occurred, and expands notification duties to affected individuals in defined circumstances. Its penalty ceiling for general violations is 3 billion Vietnamese dong, with cross-border transfer breaches exposed to fines of up to 5% of prior-year revenue.

Because the records cover international flights, EU and UK residents are almost certainly represented, which brings GDPR and UK GDPR into scope for any controller established in or targeting those markets. Passport numbers and travel history fall squarely within personal data, and passenger data processing has drawn repeated scrutiny from European data protection authorities.


文章来源: https://thecyberexpress.com/220-million-airline-passenger-crew-data-expose/
如有侵权请联系:admin#unsafe.sh