Archive for Vietnam

A misconfigured database exposed 220 million traveler records tied to Vietnam

Posted in Commentary with tags on September 8, 2026 by itnerd

Security researchers found an exposed Elasticsearch cluster holding roughly 220.7 million passenger and crew records from a Vietnam-linked Advance Passenger Information System, spanning January 2017 through April 2026, reachable through a cloud-based path that accepted default credentials. Singapore Airlines’ security team helped coordinate the response, and the database was secured June 8, five days after researchers reported it, with no confirmed evidence anyone malicious got there first.

More details here: Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

Jason Brown, Director of Customer Advisory Counter Fraud Lead, iCOUNTER had this to say:

“A passport number tied to a name, date of birth, and travel history is a complete identity kit, not a fragment. Stolen card numbers get frozen the moment a bank flags fraud. A passport record doesn’t expire that way. It stays useful for building a synthetic identity or supporting document fraud years after the original trip happened, which is why nine years of records sitting in one place matters more than the headline number suggests. Fraud is only half of it. Nation-state actors use exactly this kind of collection to track individuals of interest and their movement for espionage and other targeting. Travel history at this depth is a pattern of life record, not just an identity record. 

What actually got this database exposed is almost mundane compared to what was in it. Direct access to the cluster was locked down, a second cloud path was not, and that one accepted default credentials. It is the same failure I chased for years on the law enforcement side, someone secures the route they built and never finds the one they inherited, and the route nobody documented is still running the password it shipped with. The good news here is narrower than the headlines suggest. 

Researchers reported and it was secured within five days. That is not the same as knowing nobody else got there first, as there were no server logs and scanning platforms had the host indexed as a database years before anyone reported it. But a system like this is not Vietnam’s exposure alone. Every airline that fed passenger data into it, and every country whose citizens transited through, inherited that risk the moment it was accessible, whether or not anyone malicious got there first. The response should be the same as if this had been confirmed stolen: assume the exposure window was real, and go check what else in your own vendor chain is reachable by a path nobody documented and a password nobody rotated.”

This would be a really good time to check to see if you have the same issues. Because you do not wish to be sitting on a ticking time bomb now would you.

Hackers Target Vietnam In Complex Supply Chain Attack

Posted in Commentary with tags , on December 28, 2020 by itnerd

Vietnam appears to have been the target of a complex supply chain attack by unknown hackers utilizing malware. Targets were Vietnamese private companies and government agencies by inserting malware inside an official government software toolkit. This is according to a report from ESET:

ESET researchers uncovered this new supply-chain attack in early December 2020 and notified the compromised organization and the VNCERT. We believe that the website has not been delivering compromised software installers as of the end of August 2020 and ESET telemetry data does not indicate the compromised installers being distributed anywhere else. The Vietnam Government Certification Authority confirmed that they were aware of the attack before our notification and that they notified the users who downloaded the trojanized software.

I find it difficult to believe that the Vietnam Government Certification Authority or VGCA was aware of this seeing as the day that ESET released their report the VGCA admitted to the security breach and published a tutorial on how users could remove the malware from their systems. So read into that what you will. I read it as “or crap we got caught out and we now have to make it look like we were on top of things.”