220 Million Records, Nine Years, One Open Database
Kinryu Labs found an Elasticsearch cluster reachable from the open internet on June 3, 2026, holding 220.8 million passenger and crew records tied to flights recorded between January 2017 and April 2026. The firm secured the cluster five days later, after notifying Vietnamese authorities, national CSIRTs and the airlines it could identify.
| Detail | Figure |
|---|---|
| Discovered | June 3, 2026 |
| Secured | June 8, 2026 |
| Passenger records | 210,318,069 |
| Crew records | 10,465,631 |
| Data span | January 2017 to April 2026 |
The cluster, named pax-info, held names, dates of birth, nationalities, passport numbers and expiry dates, flight numbers, seat assignments and baggage references, tied to carriers flying across Asia-Pacific, Europe and the Middle East. Kinryu Labs traced the exposed address space to Viettel, Vietnam's state telecommunications operator, but could not confirm which organization actually operated the database. Neither Vietnamese authorities nor Changi Airport Group, named in the research as one of the implicated hubs, has published an account of how the cluster stayed open.
A Leak That Was Never Going to Stay in One Country
Advance passenger data has never had a single home. For two decades, an airline flying into a given country has typically wired itself directly into that country's own border authority, one bespoke integration per destination, repeated across every market it serves. A carrier flying two dozen routes can end up maintaining two dozen separate pipes, each built, secured and monitored on its own schedule, by whichever contractor a given border agency happened to hire.
That is what made a single misconfigured cluster tied to a Vietnamese state carrier's address space capable of holding nine years of records for routes that never touched Vietnam at all. The exposure was not really a Vietnamese problem that happened to leak; it was a structural feature of how this class of data has been plumbed everywhere, surfacing wherever the weakest pipe in the network happened to be. Fix one national endpoint and the next one, built by a different vendor to a different standard, is still there.
Europe Wrote the Fix. It Has No Switch-On Date.
The EU had already diagnosed this exact structural weakness before this leak became public. Regulation (EU) 2025/12, which entered into force on January 28, 2025, replaces the old model of carriers wiring themselves separately into each member state's border authority with a single router operated by eu-LISA, the EU's justice and home affairs IT agency. Every airline flying into, out of or within the EU is meant to send advance passenger data through that one channel instead of maintaining a separate connection per country.
The regulation's own obligations, however, do not begin until the router itself is in service, and neither eu-LISA nor the European Commission has published a date for that. Twenty months after the law took effect, the architecture it is meant to replace, the same one-endpoint-per-country pattern that let a single exposed Vietnamese cluster hold nine years of cross-border travel data, is still what every airline flying into Europe actually uses. A corporate travel department, an airline compliance team or a data protection officer who assumes the EU's centralized router already covers them is relying on a system that exists in the regulation and nowhere else yet.
Read next: 8.7 Million Airport Records Leaked in One Breach | OpenAI's Filter Cannot Make Your Chats Anonymous



