Your passport number leaked. What that actually means

A border-control database linked to Vietnam sat open with 220,783,700 traveller records in it — names, dates of birth, passport numbers and nine years of flights. You cannot change a passport number the way you change a password, so the response is different. Here is what it is worth to a stranger, and what is worth doing about it.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

A leaked passport number is an identity problem, not an account problem. Nobody can board a plane with it — boarding needs the document and your face — but paired with your name and date of birth it passes as proof of identity in places that never see the book: account openings, visa and travel forms, verification pages. Replacing the passport does retire the number, though it costs the full fee and rarely matches the risk. The steps that do match it: freeze your credit file, secure the email you book travel with, treat messages about visas and bookings as hostile, and remove the address and phone number that make an identity record usable. And in the Vietnam case specifically, there is nothing to check — the data was closed off before anyone showed it had been copied, and no set was ever published.

What sits in an advance passenger record

Every one of these fields was in the exposed cluster. Read it as a description of what airlines hand to border agencies on every international flight, not as a list unique to one country.

FieldWhat it is
Who you areFull name, date of birth, sex and nationality — the identity block an airline has to hand a border agency before you fly.
Your travel documentPassport or travel-document number, its expiry date and the country that issued it. This is the part that cannot be changed like a password.
Where you wentFlight numbers and dates, airline, departure, destination and transit airports, going back to January 2017 in the Vietnam-linked set.
How you travelledSeat assignments, baggage references and the scheduled, estimated and actual times of each flight — enough detail to describe a trip back to you convincingly.
Who it coveredPassengers and crew alike: 210,318,069 passenger records and 10,465,631 crew records in the exposed cluster, spanning nationalities rather than one country’s citizens.
What was not in itNo passwords, no payment cards and no Social Security numbers. Advance passenger data is an identity-and-itinerary file, not an account.

Sources: Kinryū Labs’ disclosure as reported by BleepingComputer on 8 September 2026, with follow-up coverage in Security Affairs and BetaNews. Discovery 3 June 2026, access closed 8 June 2026. No organisation has confirmed ownership of the database, and no evidence has been published that the data was copied or offered for sale.

1. What happened, without the rounding

On 8 September 2026 researchers at Kinryū Labs published their account of an Advance Passenger Information System database that had been reachable from the internet through a chain of misconfigurations and default credentials. The cluster held 220,783,700 entries — 210,318,069 passenger records and 10,465,631 crew records — covering flights from January 2017 to April 2026, and the work appears linked to Vietnam. Two details get dropped in most retellings and both matter. The database was found on 3 June 2026 and closed on 8 June, so the window was five days and it ended three months before you read about it. And no organisation has confirmed owning it: Singapore Airlines’ security team helped coordinate the response, Changi Airport Group looked into it and declined to comment, and Vietnamese authorities did not reply. The researchers found no ransom notes and could not find the data offered for sale, but without server logs they could not rule out that somebody copied it.

2. Why a passport number is a different kind of loss

Almost every breach guide ends with the same instruction: change the password. That advice exists because passwords are cheap to replace. A passport number is not. It stays valid for the life of the book, it is printed on an object you are required to keep, and the only way to retire it is to buy a new document. It sits with the small set of identifiers that follow a person around — date of birth, Social Security number, driving-licence number — and our guide to the IDScan licence exposure makes the same point about scanned IDs. The practical consequence is that the response changes shape. You are not closing a door; you are making the thing behind it less useful.

3. What someone can actually do with it

Start with what they cannot do: board a flight as you. That needs the document and, increasingly, a face that matches the chip in it. What the number does is satisfy checks that never see the passport — account opening at banks and exchanges that accept a document number as identity, visa and travel-service forms, verification pages that ask for a number and an expiry date, hotel and hire-car records in countries that log them. Add the name and date of birth from the same record and you have a package that passes as a person in writing. None of this is instant, which is why the effect of identity exposure is measured in months rather than days, and why people rarely connect the eventual account they did not open to the database that was open three years earlier.

4. The scam this shape of data produces

Travel data makes approaches specific, and specific is what gets through. The pattern to expect is a message about a document or a booking: a visa that needs revalidating, an entry record that needs confirming, an airline asking you to reconfirm a trip, a refund for a flight that was genuinely delayed. The reason it works is that the sender can cite something true — a real route, a real date, a real seat. Judge these on the route rather than the contents: open the airline’s own app, type the consulate’s address yourself, and treat any request for a passport number, a document photo or a payment as the end of the conversation. Government agencies do not text people about their travel history, and no legitimate service needs a photo of your passport to tell you whether you were in a leak.

5. What to do now, in order

Freeze your credit file at Equifax, Experian and TransUnion if you are in the United States — free, about ten minutes each, and the one measure that blocks rather than reports when a name and date of birth are in circulation. Turn on two-factor authentication on the email address you book travel with, since that inbox holds every itinerary and every booking reference you have. Check statements and any account where you uploaded a document for identity verification. Keep the passport unless something concrete says otherwise, and note the number somewhere private so you can tell later whether a record refers to your current book or an old one. Our post-breach guide runs through the general version in seven steps.

6. The part you can still change

You cannot recall a passport number from a database somebody left open in 2017, and you cannot check a set that was never published. What you can change is everything sitting next to it. A current home address, a phone number, an age and a list of relatives are what turn an identity record into a call that sounds legitimate — and those are not locked in a border system. They are published, indexed and sold by people-search and data-broker sites that rebuild the profile from public records every few weeks. Removing them is the one step in this guide with a measurable result, and it is the step that keeps paying after the next leak, because the next leak will also need an address to be worth anything.

The passport number is fixed. The rest of the profile is not.

No service can search a database that was never published — and we will not pretend otherwise. What we can show you is the part that is published: your home address, phone number, age and relatives, listed by 499 broker and people-search sites, plus whether your email appears in the breach sets that are public. That is the context a stranger needs to turn a document number into a convincing approach. The scan is free.

See what is published about me — free →
Common questions

Leaked passport numbers, answered

Can I check whether my passport number was in the Vietnam APIS leak?

No, and be sceptical of anything that says otherwise. The data was sitting in a misconfigured database rather than posted on a forum: researchers found it, reported it, and access was closed. Nothing was published, so there is no set for a breach-checking service to index — ours included. If you flew to, from or through Vietnam between January 2017 and April 2026, it is reasonable to assume your travel document was in there, and reasonable to note that nobody has shown the data was ever copied. A site offering to search the APIS leak for your passport number is collecting passport numbers.

Can someone travel on my passport number?

Not on the number by itself. Boarding needs the physical document, and at most borders a face that matches the chip inside it. What the number does is answer questions: it is accepted as proof of identity in places that never see the document — opening accounts at some banks and exchanges, verification forms, visa and travel services, hotel and car-hire records in several countries. The risk is someone using your identity in writing, not someone walking through an airport as you.

Should I get a new passport?

Usually not because of a leak alone. A renewed passport carries a new number, so replacing it does close off the old one — but you pay the full fee, you lose the book for several weeks, and the exposure that follows you around is your name, date of birth and address rather than the number. Replace it if you see the number actually being used against you, if a consulate or your bank tells you to, or if your renewal is due soon anyway. What you must not do is report the passport lost or stolen when it is not: that is a false statement on a government form, and it invalidates a document you are still carrying.

Is a passport number dangerous on its own?

On its own it is a string of characters that proves nothing. Paired with your name and date of birth — which were in the same records — it becomes an identity package that passes a surprising number of checks by post, by phone and by web form. That is the honest shape of the risk: not dramatic, not nothing, and not fixable by changing a password. Identity data works slowly, and it works by being combined.

Why does my flight history matter? It is just where I went.

Because it is what makes an approach believable. Somebody who can name the flight you took, the seat you sat in and the baggage tag on your case is not a stranger guessing — that is the raw material for "there is a problem with your visa", "your booking needs reconfirming", or a call that opens by reciting a trip you really took. Itinerary data is also how a determined person works out when a home is empty. The passport number is the part that cannot be reissued; the travel history is the part that makes it persuasive.

What is APIS, and why does a government have my flight details?

Advance Passenger Information is the data airlines are required to send border agencies before a flight arrives: who is on board, what document they are travelling on, and the flight itself. Most countries run some version of it, and you consent to it implicitly every time you book. It means a copy of your passport details exists in systems you never chose, operated by parties you have no relationship with — which is exactly why this exposure reached people who have never dealt with any Vietnamese company.

Do I need to report this to my embassy or to the police?

Not for an exposure with no evidence of misuse. Embassies and passport agencies act on documents that are lost, stolen or being used fraudulently, and a database that was closed before anyone proved it had been copied is none of those. If you later find your passport number attached to an account you did not open or a border record you cannot explain, that is the point to report it — to the passport authority that issued the document, and to the institution holding the account.

What should I actually do this week?

Assume your identity block is in circulation and make it less useful. Freeze your credit file at all three bureaus if you are in the United States, so the name-plus-date-of-birth combination cannot open an account. Turn on two-factor authentication on the email address you book travel with, because that inbox holds every itinerary you own. Treat travel-themed messages as hostile and check bookings in the airline’s own app rather than through a link. Then get the address and phone number that sit beside your name off the broker sites that publish them — that part you can actually change.

You cannot reissue a date of birth

The identifiers that follow you around are fixed. The address and phone number published beside them are not — and those are what make a stolen record usable. See which sites list yours, free, in about a minute.

Run my free exposure scan →