An exposed database tied to an Advance Passenger Information System left 220 million passenger and crew records open, and the contents read like an identity thief’s wish list: full names, passport numbers, dates of birth, nationalities and flight details, spanning 2017 to 2026. No zero-day, no ransomware, no sophisticated intrusion. Just a sensitive dataset reachable when it should not have been. It is a blunt reminder that the fastest way to lose a fortune in data is not to be hacked, but to leave the door open.
Why this data is so dangerous
Passenger information is a uniquely toxic combination. A passport number plus a date of birth plus a full name is enough raw material to impersonate someone, open accounts, or pass identity checks that assume such details are private. Add nationality and detailed travel history and you have a profile that supports targeted fraud, phishing that quotes real trips, and even physical-world risk for people whose movements should stay confidential. Unlike a password, none of this can be rotated: you cannot reissue a date of birth.
The nine-year span makes it worse. This is not a snapshot of current travellers but a longitudinal record of who went where over the better part of a decade. For the individuals in it, exposure is effectively permanent, and the data retains value to criminals for years. Breaches like this do not age out; they circulate, get combined with other leaks, and resurface in fraud campaigns long after the headline fades.
Exposure is not the same as hacking
It is tempting to picture every breach as a break-in, but a large share of the biggest data losses are simply exposures: a database with no authentication, a storage bucket set to public, a backup left reachable. There is no clever exploit to admire, and that is precisely the point. The failure is in configuration and oversight, not in some unstoppable adversary, which means it is also preventable with unglamorous discipline.
The uncomfortable truth is that attackers do not need to be good when defenders leave data unguarded. Automated scanners continuously sweep the internet for open databases and misconfigured storage, and they find them constantly. A dataset like this does not require a targeted campaign to leak; it only requires being reachable and being noticed, and both happen faster than most organisations audit their own footprint.
What the people in that database now face
For the individuals whose records were exposed, the fallout is real and hard to undo. Passport numbers and birth dates are used as identity anchors by banks, governments and countless online services, and they cannot be reissued on a whim. Anyone in the dataset should treat unsolicited contact referencing their travel or documents with suspicion, since phishing that quotes a genuine trip is far more convincing than a generic scam. Watching financial accounts and, where available, placing fraud alerts or freezes on credit are reasonable precautions. The frustrating part is that the victims did nothing wrong and can do little to fully protect themselves; the failure was upstream, in whoever left the data reachable, which is exactly why the duty to guard this kind of data sits so heavily on the organisations that hold it.
Keep less, expose less
The breach also indicts a habit few organisations examine honestly: keeping everything forever. Nine years of passport numbers is nine years of liability, and most of it serves no live operational purpose. Data minimisation, holding only what you need for only as long as you need it, is one of the cheapest and most effective controls available, because data you never collected or already deleted cannot leak. It is unglamorous and easy to defer, which is precisely why it gets skipped. Pair it with a clear inventory of where sensitive data actually lives and who can reach it, and the worst-case blast radius of any single misconfiguration shrinks dramatically. You cannot lose what you chose not to keep.
How to avoid being the next one
- Know what you expose. Map your internet-facing assets, databases and storage the way an attacker would; you cannot protect an asset you forgot you had. An external penetration test surfaces exactly this.
- Enforce authentication and least privilege on every data store, and treat “temporarily open for testing” as a production incident waiting to happen.
- Minimise and age out sensitive data. If you do not need nine years of passport numbers, do not keep nine years of passport numbers; data you do not hold cannot leak.
- Watch the endpoints and APIs that front your data, since a leaky interface is as good as an open database. API security monitoring and continuous vulnerability management keep that surface honest.
Regulation is watching too
Beyond the harm to individuals, exposures like this increasingly carry a regulatory bill. Modern data-protection regimes treat a leak of personal data as a reportable event with tight deadlines and real financial penalties, and “the database was simply misconfigured” is not a defence, it is an admission. Regulators have been clear that failing to secure data you chose to collect is itself the violation, regardless of whether a sophisticated attacker was ever involved. For any organisation holding personal information, that turns basic hygiene, authentication, access control and knowing your own footprint, from a nice-to-have into a compliance obligation with teeth. The cheapest time to get this right is always before the notification letters go out.
The bottom line
Two hundred and twenty million records did not fall to a genius attacker; they fell to a door left unlocked. For the people in that database the damage is lasting, because identity documents and birth dates cannot be reset. For everyone running systems that hold personal data, the lesson is deflating in its simplicity: most catastrophic leaks are self-inflicted, and the cure is knowing your own attack surface and guarding it with discipline. If sensitive data leaks despite your best efforts, dark-web monitoring at least tells you it is out there before the fraud starts. Not sure what your organisation is quietly exposing right now? Ask us to look before an automated scanner does.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.
