Your Passport Number Isn't a Secret Any More. Here's What to Do
A leaked travel database exposed 220 million passport and flight records. Flown via Vietnam? Here's what it means and how to spot the scams that follow.
Published 2026-09-14
The short version
- An open database linked to a Vietnamese organisation exposed 220 million passenger and crew records, including passport numbers and flight details, from 2017 to 2026.
- If you've flown to, from or through Vietnam since 2017, assume your passport number and travel history are no longer private.
- You can't change a passport number or a travel history, so the defence is suspicion: expect phishing that quotes a real trip.
- Share passport scans as rarely as possible, verify every travel message through a channel you choose, and look out for IDLock on myGov.
What was in the APIS leak?
Before your plane lands, the airline sends the destination government a list of everyone on board. It's called Advance Passenger Information, or APIS, and it's one of the most routine data transfers in travel. It's also one of the most sensitive.
On 3 June, researchers at Kinryū Labs found an unsecured database on the open internet holding an APIS feed linked to a Vietnamese organisation. It contained roughly 107 GB of data across 29 indexes: 220 million passenger and crew records covering January 2017 to April 2026.
Each record included a full name, date of birth, sex, nationality, passport number, passport expiry date and issuing country. Alongside that sat the flight: flight number and date, airline, origin, destination, transit airports, seat, baggage reference and scheduled and actual times.
The 220 million figure overstates the number of people, because frequent flyers appear once per trip. The researchers still estimate the real total in the tens of millions. It's also still unknown whether anyone downloaded, sold or ransomed the data before the database was secured. That uncertainty is the problem. When nobody can tell you whether your data was copied, the safe assumption is that it was.
Am I in it?
If you've flown to, from or through Vietnam since the start of 2017, you're likely in this dataset. Ho Chi Minh City and Hanoi are common stopovers on routes out of Australia, so this reaches well beyond people who holidayed in Vietnam. A transit on the way to Europe counts.
There's no public lookup tool for this leak, and there probably won't be. So rather than waiting for confirmation, act as though your passport number is public. For a lot of frequent travellers it probably already was, because it's been typed into booking forms, photocopied at hotel desks and emailed to tour operators for years. This leak just makes it certain.
Why this breach is different from the usual kind
The same week, 32.8 million Condé Nast user records, covering readers of Vogue, The New Yorker, GQ, Glamour, WIRED and Vanity Fair, were listed for sale for US$15,000. The seller claims email addresses for all of them, plus names, postal addresses, dates of birth and phone numbers for some. No passwords and no card details.
That's the ordinary kind of breach. It's annoying and it means more spam and more phishing, but most of it can be managed. You can change an email address, filter spam and put an alias in front of your inbox.
APIS is the other kind: a government identity document tied to your movement history. You can't change your date of birth. You can't recall a passport number until the passport expires. And you definitely can't change where you've been. Both get called a "breach", but they're very different problems.
It's also a reminder of an uncomfortable asymmetry. This is data you're legally required to hand over to travel, collected for border security. You didn't opt in, you couldn't opt out, and when it leaked from an organisation you've never heard of, there was nobody for you to ask. If you ask the Australian Government what it holds about you, there's at least a formal process. With a foreign data handler running an open server, there usually isn't.
What scams should I watch for?
A passport number on its own isn't enough to empty your bank account. The risk comes from what it helps someone do next.
The biggest one is travel-themed phishing. Someone holding your flight history can write an email that mentions a real trip: your actual flight number, the date you flew, your seat. "Your baggage claim from flight VN-something on 14 March needs verification." "A refund is owed on your cancelled leg through Hanoi." Because the details are right, the message feels real, and that's what makes it work.
The second is identity verification you didn't start. Your name, date of birth and passport number are exactly what many online identity checks ask for. Add a leaked email address and phone number from a breach like Condé Nast, and someone has most of what they need to try opening an account in your name.
The third is being talked into sending more. Just this month, the digital bank Revolut confirmed that copies of customers' passports and licences were sent to someone who had faked official data requests from a genuine government email domain. The attacker didn't hack anything. They sounded official.
What to do this week
You can't take your passport number back. What you can do is make it much less useful to anyone who has it.
- Treat your passport number as public. Stop thinking of it as a secret that proves who you are. Anyone who asks for it as proof of identity is asking for something a stranger might have.
- Be suspicious of any travel message that quotes a real trip. Don't click links in emails or texts about refunds, baggage, visas or loyalty points. Open the airline or booking app yourself, or type the website address in, and check there.
- Stop emailing passport scans. Hotels, tour operators and visa agents often ask for a copy. Ask whether showing it at check-in will do instead. If you must send one, write across the image who it's for and the date, so it's less useful if it leaks.
- Delete old copies you've sent. Search your sent mail for "passport" and delete old attachments, and clear passport photos out of your phone's camera roll and cloud backups.
- Watch for identity checks you didn't start. If you receive a one-time code, a new-account welcome email or a credit enquiry you don't recognise, act straight away. IDCARE, Australia's free not-for-profit identity support service, can help, and you can ask the credit reporting bodies for a free ban on your credit file.
- Look out for IDLock. The Australian Government announced it on 31 August. It will sit inside myGov and let you block, unblock and monitor the use of your passport or licence for online verification. Testing starts later this year, with national rollout in 2027. We'll update this page when it opens.
- Check your email on Have I Been Pwned. It's free, and it will show which ordinary breaches your address is in, which are the ones scammers pair with travel data.
Protecting your documents while you travel
Most passport exposure happens in small, forgettable moments. A booking confirmation opened on airport WiFi. A check-in form filled out on a hotel network shared with three hundred other guests. A scan uploaded to a visa site from a café.
Public and hotel networks are the weak spot, and a trustworthy VPN is the standard fix: it encrypts everything between your device and the internet, so nobody else on the network can see what you're sending. We keep a separate site, NoSpyOnVPN, that looks at the handful of VPN providers that hold up under scrutiny, which is worth checking before your next trip.
Keep it simple otherwise. Carry your passport in an inside pocket or a closed pouch rather than a back pocket or an open bag. Keep a photo of the details page in an encrypted notes app or password manager, not loose in your camera roll. And when a hotel desk asks to keep your passport "for a few minutes", ask for it back once they've checked it.
See VPNs that hold up on hotel and airport WiFi at NoSpyOnVPN →
Can I complain, and who to?
If an Australian business such as a travel agent, airline or hotel group mishandles your passport details, complain to them in writing first. If you don't get a proper response within 30 days, you can take it to the Office of the Australian Information Commissioner (OAIC). In the UK, the ICO handles this. In the EU, it's your national data protection authority.
For a leak like this one, from a foreign organisation with no obvious contact point, your options are honestly limited. That isn't a reason to do nothing. It's a reason to put your effort into what you can control: fewer copies, more suspicion, and the right protections set up before the next trip.
For the practical, physical side of that, from document pouches to the rest of a travel privacy kit, our sister site NoSpyTravel has you covered.
Frequently asked questions
Can someone steal my identity with just my passport number?
A passport number alone usually isn't enough, but combined with your name, date of birth, email and phone number from other breaches, it can help someone pass online identity checks or write a convincing scam. Treat it as public and watch for identity checks you didn't start.
How do I know if I'm in the Vietnam APIS data leak?
There's no public lookup tool. If you've flown to, from or through Vietnam since January 2017, it's safest to assume your passport and flight details were exposed.
Should I get a new passport after a data breach?
A leaked passport number alone isn't usually grounds for a replacement. Focus on suspicion of travel-themed messages, a credit ban if you see signs of misuse, and IDLock when it becomes available. If your physical passport is lost or stolen, report it to the Australian Passport Office straight away.
Is it safe to email a copy of my passport to a hotel?
Avoid it where you can. Ask whether showing it at check-in will do. If you must send a copy, write who it's for and the date across the image, then delete it from your sent mail afterwards.
Ready to act on this?
We've reviewed the tools so you don't have to.