LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Vietnam Airlines Data Breach (2025)

HIGH severityConfirmedHow we verify

Vietnam Airlines Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 20, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Vietnam Airlines Data Breach (2025)

Reported June 20, 2025. Approximately 7.3M people affected.

HIGH
Severity
7.3M
People affected
5
Data types exposed
June 20, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Vietnam Airlines disclosed a data breach on 20 June 2025 affecting 7.3 million individuals, with names, dates of birth, email addresses, phone numbers, and loyalty-program details exposed. Passengers and loyalty-program members are urged to verify whether their information was involved and to monitor accounts for unusual activity.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
7.3M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For millions of Vietnam Airlines customers, the exposure of personal details can mean more than a distant cybersecurity headline. When names, contact information, dates of birth and loyalty programme records leave an organisation’s systems, the practical stakes include targeted phishing, account takeover attempts and the long-term risk that those details will be reused in fraud. Public reporting indicates that 7.3 million unique customer email addresses were among the records involved, making the incident relevant to a large share of the airline’s passenger base.

The data became public in October 2025 after it was stolen from Salesforce environments used by multiple companies. Vietnam Airlines was named among the organisations affected. Exact methods of initial access remain limited in public detail, yet the volume and nature of the records make clear why ordinary travellers and loyalty members have reason to pay attention.

What happened

According to public reporting, a breach of Vietnam Airlines’ Salesforce environment occurred in June 2025. The incident was reported on 20 June 2025. In October 2025, data stolen from the Salesforce instances of multiple companies was publicly released by a hacking group calling itself “Scattered LAPSUS$ Hunters.” Vietnam Airlines was listed among the affected organisations. The release included 7.3 million unique customer email addresses together with associated personal details. Public sources do not provide further confirmed information on the precise intrusion technique, the full duration of unauthorised access, or any ransom demand. The scale of the email exposure is the clearest quantitative figure available.

Inside shinyhunters

ShinyHunters is a well-documented cybercriminal group that has operated for several years, specialising in large-scale data theft and the subsequent sale or public dumping of stolen databases. The group is known for targeting cloud platforms, customer-relationship systems and other repositories that hold high volumes of personal and commercial data. Its typical tactics have included social-engineering campaigns against employees, exploitation of misconfigured cloud services, and the use of stolen credentials. Prior activity attributed to the group has involved breaches of technology, retail and service companies, with data often appearing on underground forums or leak sites. In the present case the public release was claimed by actors identifying themselves as “Scattered LAPSUS$ Hunters”; that listing remains an unverified claim by the group rather than an independently confirmed attribution. Public knowledge of ShinyHunters’ methods supplies context for how such Salesforce-related incidents commonly unfold, but does not establish additional specifics about the Vietnam Airlines intrusion beyond what has been reported.

About Vietnam Airlines

Vietnam Airlines is the national flag carrier of Vietnam, operating extensive domestic and international passenger and cargo services. Like other major airlines, it maintains large customer databases that support booking systems, frequent-flyer programmes, customer-service platforms and marketing operations. These systems routinely store contact details, travel histories and loyalty membership information. Because airlines sit at the intersection of travel, identity verification and commercial loyalty schemes, a compromise of their customer records can affect both individual travellers and the organisation’s operational trust. The use of Salesforce as a customer-data platform is common across the sector; any breach of that environment therefore carries consequences for the volume of personal information typically concentrated there.

What data was at risk

Public reporting names the following categories of data as exposed: dates of birth, email addresses, loyalty programme details (including membership numbers), names and phone numbers. The figure of 7.3 million unique customer email addresses is the only scale metric confirmed in the available summary. No further breakdown of file contents, exact record counts beyond the email total, or confirmation of additional data types has been disclosed. Organisations of this type commonly hold passport or identity-document references, payment-token information and detailed travel itineraries; whether any of those elements were present in the stolen Salesforce data remains unconfirmed. Readers should therefore treat only the named categories as established and regard other possibilities as speculative.

Why it matters

For individuals, the combination of name, date of birth, email, phone number and loyalty membership number creates a ready-made profile for social-engineering attacks. Fraudsters can craft convincing messages that reference genuine loyalty accounts or recent travel, increasing the chance that recipients will click malicious links or disclose further credentials. Phone numbers and emails also enable SIM-swap attempts or credential-stuffing attacks against other services where the same contact details are reused. For Vietnam Airlines the incident raises operational and reputational considerations: customer trust, potential regulatory scrutiny under data-protection regimes, and the cost of remediation and notification. Because the data were released publicly rather than merely held for ransom, the exposure is effectively permanent; once circulating, the records can be copied and resold indefinitely. The absence of Reported Details on encryption status or additional safeguards means affected people must assume the information is usable by third parties.

If your data was in this breach

Begin by treating any unsolicited communication that references Vietnam Airlines, loyalty points or travel details with heightened caution. Change passwords on the airline’s customer portal and on any other accounts that share the same email address or password. Enable multi-factor authentication wherever it is offered, preferably using an authenticator app rather than SMS. Monitor bank and credit-card statements for unexpected charges and consider placing a fraud alert with credit-reporting agencies if you reside in a jurisdiction that provides that option. Review loyalty-account activity for unauthorised redemptions. Finally, readers can run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets; such a check provides an early indication of wider circulation and helps prioritise further protective steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyVietnam Airlines security record
63/100
DoxxScan™ · Moderate doxx risk
C+ 73Fair record

2 reported incidents on record.

See Vietnam Airlines’s full breach history →
RelatedMore incidents at Vietnam Airlines

More recent breaches

Sysco Data Breach (2026)June 15, 2026American Tower Data Breach (2026)June 12, 2026Ralph Lauren Data Breach (2026)June 11, 2026Madison Square Garden Sports Data Breach (2026)June 5, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Vietnam Airlines Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram