Passenger passport and flight data exposed across 220 million records
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 9th, 2026.
Travelers may face long-lived identity and targeting risks after an exposed database revealed two hundred twenty million seven hundred eighty three thousand seven hundred passenger and crew records linked to Vietnam. The records covered January 2017 to April 2026. They included names, birth dates, passport details, flight routes, seat assignments, and baggage references. Researchers reached the Elasticsearch cluster by chaining two security misconfigurations, including a cloud-based path that accepted default credentials. Access was closed on June 8th, but missing server logs mean no one can determine whether the data was copied before then.
The total represents journeys rather than unique people, so frequent travelers may appear more than once. Even so, the presence of many international airlines gives the exposure potentially global reach. Passport and itinerary details can support convincing impersonation, phishing, or surveillance. Leaders should treat this as a data-governance problem, not just a database configuration mistake. Defenders should identify every reachable data store, remove default credentials, and preserve the access logs needed to answer breach questions. Audit every path to sensitive databases, rotate exposed credentials, and retain logs for investigation.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.news.