Data BreachBleeping Computer
6.0 — HIGH
220 million traveler records exposed in Vietnam-linked APIS leak
Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A Vietnamese-linked APIS database containing over 220 million passenger and crew records was exposed due to security misconfigurations, potentially compromising sensitive travel information of international travelers.
⚙️Technical Details
Affected Systems
Advance Passenger Information System (APIS) database
Attack Vectors
Chained misconfigurations involving HTTP 401 'Unauthorized' response and default credentials
💥Impact Assessment
Severity: High
Who Is at Risk
International travelers whose passport numbers, flight details, and other personal information were stored in the exposed APIS database
🛡️Recommended Actions
1Implement robust security configurations for sensitive databases
2Regularly monitor and scan for exposed databases and misconfigurations
3Verify default credentials and authentication mechanisms to prevent unauthorized access
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
