:

220M TRAVELER RECORDS EXPOSED IN VIETNAM APIS LEAK

DEV DESK1 MIN READ
TUE, SEP 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

An unsecured Advance Passenger Information System (APIS) database exposed 220 million passenger and crew records. Researchers accessed the Vietnam-linked system through default cloud credentials, revealing sensitive data spanning nearly a decade.

The exposed database contained names, passport numbers, dates of birth, nationalities, and flight details for records dating from 2017 to 2026. Researchers discovered the breach through a cloud-based access path secured only by default login credentials, highlighting a critical security gap in the travel infrastructure. APIS databases store passenger information submitted to aviation authorities ahead of flights. The scale of this exposure affects travelers globally and raises concerns about the security protocols protecting sensitive travel data. The Vietnam connection suggests the database belonged to or was linked to Vietnamese aviation operations. The breach underscores persistent vulnerabilities in systems handling high-volume personal data, particularly when default authentication mechanisms remain unchanged in production environments. No information has been provided regarding notification of affected parties or remediation efforts.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Microsoft is releasing a record number of security patches today as AI models rapidly discover software vulnerabilities. The company has now broken its patch Tuesday record three times in just a few months.

JUST NOWIndustry Desk

Third-party applications connected to Google Workspace can retain access long after becoming obsolete, creating potential breach vulnerabilities. A new webinar examines how overly permissive integrations threaten organizations.

JUST NOWSecurity Desk

Threat actors are abandoning traditional AI coding assistants in favor of multi-agent frameworks that automate every phase of cyberattacks. The shift enables attackers to scale credential theft operations with minimal human intervention.

1H AGOAI Desk

LG smart TVs continuously collect and upload user data about homes and viewing habits, even during offline or standby modes, according to testing by YouTube channel Gamers Nexus.

1H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.