Back to all lessons
Awareness Lessons
last month

Default Credentials Expose 220 Million Traveler Records in APIS Database Leak

An Advance Passenger Information System (APIS) database was left publicly accessible due to a combination of security misconfigurations and the use of default credentials, exposing 220 million sensitive passenger and crew records spanning nearly a decade. This failure highlights how foundational security hygiene — particularly changing default credentials and restricting public access to sensitive databases — remains critically neglected even in systems handling highly sensitive personal and travel data. The exposure of passport numbers, dates of birth, and flight details creates significant risk for identity theft, targeted phishing, and potential surveillance of travelers across multiple nationalities. The incident underscores that databases containing personally identifiable information (PII) must never be internet-facing without strong authentication, encryption, and access controls in place.

Tactical Insight

Immediate actions

  • Audit all internet-facing databases and systems immediately to identify any use of default or weak credentials and replace them with strong, unique passwords.
  • Restrict public internet access to sensitive databases by placing them behind firewalls, VPNs, or private network segments with explicit allowlisting.
  • Conduct an inventory scan of all exposed assets using tools like Shodan or internal vulnerability scanners to identify unintended public exposure.

Long-term improvements

  • Implement a mandatory hardening checklist for all new system deployments that explicitly requires changing default credentials before go-live.
  • Adopt a data minimization and classification policy to ensure that highly sensitive PII databases receive the highest tier of access controls and monitoring.
  • Establish a regular third-party penetration testing and security audit program focused on externally accessible infrastructure.

Detection measures

  • Deploy continuous monitoring and alerting on database access logs to detect anomalous query volumes or unauthorized access attempts in real time.
  • Integrate threat intelligence feeds and external attack surface management (EASM) tools to proactively identify misconfigured or exposed assets before researchers or attackers do.
  • Set up a responsible disclosure (bug bounty) program so that external security researchers have a clear, trusted channel to report vulnerabilities promptly.