Massive data breach sees 220 million traveler records exposed — nine years of airline info leaked including…

https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-2560-80.jpg
  • Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records
  • Data included PII, travel details, seat assignments, and baggage references from 2017–2026
  • Archive locked and there is no evidence yet of dark web sale

Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.

In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.

The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure....

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more