Quick Answer
Vietnam APIS data leak: 220M traveler records exposed. Covers 2014-2024 travelers. Data: name, passport, DOB, nationality, flight info. Vietnam-linked threat actor. One of the largest government breaches ever. Cross-border impact: foreign travelers, business travelers, government officials (BleepingComputer, 2026).
Data last verified September 2026 from BleepingComputer and security research reports.
Vietnam APIS data leak — what we know
| Field | Detail |
|---|---|
| Records exposed | ~220 million (2014-2024) |
| Data types | Name, passport, DOB, nationality, flight info, itinerary |
| Database | Vietnam APIS (Advance Passenger Information System) |
| Threat actor | Vietnam-linked 'VietnamAPT' (per BleepingComputer) |
| Discovery date | Early 2026 |
| Public disclosure | August 2026 (BleepingComputer report) |
| Where sold | Dark web forums, cybercrime marketplaces |
| Asking price | ~$5,000-10,000 per 1M records (estimated) |
Source: BleepingComputer (2026).
Why APIS data is sensitive
APIS data is sensitive because it contains: (1) Passport numbers — primary government ID document, can be used for identity theft, (2) Travel history — sensitive for business travelers, government officials, and individuals with privacy concerns, (3) DOBs — combined with name enables identity theft, (4) Itinerary data — used by law enforcement and intelligence agencies to track individuals, (5) Nationality and visa data — used for immigration enforcement. The combination of APIS data across multiple countries can be cross-referenced to build a complete profile of an individual's travel history (US Department of Homeland Security, 2026).
What is APIS (Advance Passenger Information System)?
APIS is a government border security system used by many countries including the US, UK, EU, Canada, Australia, and Vietnam. APIS requires airlines to submit passenger information (full name, passport number, nationality, DOB, gender, flight number, origin/destination airports) to destination countries before flight arrival. APIS data is used for: (1) Immigration enforcement, (2) Customs enforcement, (3) Counter-terrorism screening, (4) Law enforcement investigations, (5) Public health contact tracing. APIS data is retained for varying periods depending on the country (US Department of Homeland Security, 2026).
Who is affected by the Vietnam APIS leak?
The Vietnam APIS leak affects: (1) All international travelers who entered or left Vietnam between 2014 and 2024, estimated at 220 million+ people, (2) Foreign tourists visiting Vietnam (US, EU, Asian, Australian), (3) Business travelers, (4) Vietnamese citizens traveling abroad, (5) Government officials and diplomats, (6) Military personnel transiting through Vietnam, (7) Refugees and asylum seekers who passed through Vietnam. The leak is particularly sensitive for individuals who traveled to Vietnam for sensitive reasons (journalism, activism, business) and who may face consequences if their travel is exposed (BleepingComputer, 2026).
What is the data being sold for?
The data is being sold for several malicious purposes: (1) Identity theft — using passport numbers to open fraudulent accounts, (2) Account takeover — using name, DOB, and passport to bypass identity verification at banks, (3) Travel surveillance — tracking the movement of specific individuals, (4) Targeted phishing — using travel history to make phishing emails more convincing, (5) Government espionage — foreign intelligence agencies can use the data to track officials, (6) Cross-border crime — smuggling, trafficking, and money laundering operations can use legitimate passport data to move people, (7) Insurance fraud — using identity to file fraudulent insurance claims (BleepingComputer, 2026).
How does the Vietnam APIS breach compare to other government breaches
| Breach | Records | Year |
|---|---|---|
| Vietnam APIS | 220M | 2026 |
| Equifax (US) | 147M | 2017 |
| Yahoo (global) | 3B | 2013-2014 |
| OVH data center fire | — | 2021 |
| US OPM (Office of Personnel Management) | 22M | 2015 |
| India Aadhaar | 1.1B | 2018 |
| Philippines COMELEC | 55M | 2016 |
Source: Privacy Rights Clearinghouse, BleepingComputer (2026).
Vietnam's data security concerns
Vietnam has been a growing source of cyber threats and a target of cyber attacks. Vietnam's data security concerns: (1) Rapid digitization — Vietnam has been digitizing government services rapidly, sometimes ahead of security investments, (2) Sophisticated threat actors — Vietnam-linked APT groups (OceanLotus, APT32) are known for sophisticated attacks, (3) Limited cybersecurity workforce — Vietnam has fewer cybersecurity professionals than larger economies, (4) Cross-border data flows — Vietnam handles large amounts of foreign traveler data, making it a high-value target, (5) Regulatory gaps — Vietnam's data protection law (PDPD, effective 2023) is newer and less mature than GDPR or CCPA (Vietnam Government, 2026).
What travelers should do
- Check whether you have traveled to Vietnam between 2014 and 2024 (the breach window).
- Monitor financial and credit reports for unusual activity.
- Consider placing a credit freeze with the major credit bureaus.
- Watch for phishing emails referencing Vietnam travel or passport renewal.
- Consider renewing your passport if you have traveled to Vietnam (the leaked passport number is now compromised).
- Be aware of travel surveillance — your travel history to Vietnam may be known to others.
- Consider using a passport cover or RFID-blocking sleeve for additional security.
- Monitor your passport's identity theft indicators (unfamiliar entries, visa stamps you didn't request, etc.).
What governments should do
- Issue travel advisories for citizens who have traveled to Vietnam.
- Work with international law enforcement (Interpol, FBI) to investigate the breach.
- Consider diplomatic action against Vietnam if the breach is confirmed to be state-sponsored.
- Review APIS data sharing agreements with Vietnam and other countries.
- Update border security systems to use additional authentication for travel data.
- Provide identity theft protection to affected government officials and diplomats.
- Consider transitioning to biometric or tokenized travel credentials to reduce reliance on passport numbers.
What this means for international travel data
The Vietnam APIS leak highlights the risks of international travel data sharing: (1) APIS data is collected by many countries but security standards vary widely, (2) A single breach can affect hundreds of millions of travelers from all countries, (3) Travel data is valuable to intelligence agencies, criminals, and identity thieves, (4) Travelers have limited ability to control how their data is shared, (5) International cooperation on travel data security is limited. There is a need for international standards on APIS security, including: encryption requirements, breach notification rules, and traveler consent (International Air Transport Association, 2026).
Resources and next steps
Visit identitytheft.gov for free identity theft recovery resources. The US Department of State publishes travel advisories at travel.state.gov. The International Air Transport Association (IATA) publishes APIS standards at iata.org. The US Customs and Border Protection (CBP) provides information on US APIS at cbp.gov. For Vietnam travel, register with the US Smart Traveler Enrollment Program (STEP) at step.state.gov. For cyber threat intelligence, follow BleepingComputer, KrebsOnSecurity, and The Record.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









