# 220 Million Travelers' Passports Were Sitting Behind Default Credentials


When you board an international flight, you don't choose what data you hand over. Governments mandate it. Airlines collect it and transmit it ahead of you — your name, your passport number, your nationality, your date of birth, your itinerary. The Advance Passenger Information System exists precisely so authorities can screen you before you land. You have no opt-out. You trust the system.


That trust just cost 220 million people their most sensitive travel records.


## What APIS Is — and Why This Leak Is Different


Most data breaches involve companies that at least theoretically had a choice about what they collected. APIS is different. It is a government-mandated pre-clearance system, a global requirement for international aviation. Airlines are legally obligated to transmit passenger and crew data before departure. Authorities in receiving countries use it for border screening and law enforcement lookups.


The exposed database — linked to a Vietnamese operator — held records from 2017 through 2026. Nearly a decade of cross-border movement. Researchers who discovered it found names, passport numbers, dates of birth, nationalities, and flight details sitting exposed in a cloud environment. The access method: default credentials. No sophisticated exploit. No zero-day. A username and password that nobody bothered to change.


The scale — 220 million records — points to something broader than a single airline's manifest system. APIS aggregators and regional government systems often consolidate data across carriers and routes. The exact operator has not been publicly named in early reporting, but the Vietnam connection suggests this likely covers traffic through Southeast Asian aviation hubs, which would explain why the dataset spans nine years and eight figures.


## The Geography of Exposure


Passport numbers are not like passwords. You cannot rotate them. A compromised email gets a new password; a compromised passport gets reported, canceled, and replaced — a bureaucratic ordeal that takes months and costs money, and that's assuming the holder even knows their document was exposed.


What makes travel data particularly toxic beyond the identity fraud angle is what it reveals about behavior. A passport number tells a fraudster who you are. Your flight history tells a surveillance actor where you go, how often, with what regularity, and — cross-referenced against co-traveler records in the same database — potentially who you travel with.


For most people, this means elevated fraud risk: targeted phishing using real travel details, synthetic identity construction, passport cloning schemes. For journalists, activists, dissidents, diplomats, or anyone whose travel patterns represent a security or political risk, the implications are considerably darker. Knowing that a human rights researcher flew from Hanoi to Geneva on a specific date in 2023 is exactly the kind of granular intelligence that state-level actors pay for — or in this case, may simply collect from an exposed endpoint.


## Default Credentials, Again


The access vector here deserves its own paragraph because it is inexcusable and depressingly routine.


Default credentials — factory-set usernames and passwords that ship with software, databases, and cloud services — are among the oldest attack surfaces in security. Shodan, the internet-facing device search engine, makes finding systems running default credentials trivially easy. Security teams have known this for decades. Compliance frameworks mandate credential rotation. And yet here we are: 220 million mandatory government-collected records, accessible to anyone who knew what to look for and tried "admin/admin" or the vendor default.


This is not a novel attack. It is not sophisticated adversary tradecraft. It is the digital equivalent of leaving a filing cabinet full of passports on a public sidewalk with a sign that says "unlocked."


The researchers who found this accessed it through a cloud-based path — meaning the system was not even behind a firewall or VPN. It was publicly reachable, and it was open.


## HackWire Analysis


This breach fits a pattern that should be alarming to anyone who tracks government-adjacent data infrastructure, particularly in emerging aviation markets. Southeast Asia has seen aggressive expansion of aviation capacity over the past decade — new carriers, new routes, new regional hubs — and that growth has outpaced the maturity of the backend data systems supporting it.


APIS infrastructure is not operated exclusively by governments. Third-party vendors build and operate these systems under contract across multiple countries. Those vendors range from enterprise-grade companies with real security programs to smaller regional operators whose security posture is essentially whatever shipped with the software. When you are legally required to submit your biographic data to an airline, you have no visibility into which end of that spectrum is actually handling it.


The 2017–2026 date range matters. This is not a historical archive someone forgot to delete. Records through 2026 means the exposure was live until discovery — this was an active operational system leaking in real time.


What is missing from the early coverage of this incident is any serious examination of APIS vendor accountability. The airline collects the data. The government mandates the transmission. The third-party vendor stores it. When it leaks, the airline blames the vendor, the government says it is the airline's responsibility, and the vendor is often too small or too obscure to face meaningful consequences. The 220 million people whose passport numbers are now in circulation face those consequences instead.


Defenders working in travel, aviation, and hospitality should treat APIS and passenger management systems as crown-jewel infrastructure — not peripheral databases. External attack surface reviews should specifically check for cloud-exposed APIS endpoints, default credential exposure, and whether passenger data is encrypted at rest and segregated from less-sensitive systems. Vietnam's data protection framework is still maturing, but operators in any jurisdiction handling this category of data should be treating it with the same rigor as financial records.


The breach also raises a harder question that no regulator has seriously answered: if governments mandate the collection of biometric and biographic data for entry screening, do those governments bear any liability when the collection apparatus fails? So far, the answer from every jurisdiction has effectively been no.


That needs to change.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)