Data breach
Vietnam Airlines
- Records
- 23,129,780
- Breach date
- 10 October 2025Estimated
- Added
- 11 October 2025
What was exposed
4 types of data
- Dates of birth1
- Email addresses1
- Names1
- Phone numbers1
About this breach
In October 2025, a hacker group calling itself Scattered LAPSUS$ Hunters published more than 23 million records containing personal data of Vietnam Airlines customers. According to our investigation team, the dataset appeared online on October 10, 2025, and was added to our index the following day. The airline confirmed the breach in a statement on October 14, saying that customer data processed through a third-party customer service platform operated by a global technology partner may have been accessed without authorization. Reporting by Hackread and VietnamNet traced the intrusion to the airline's Salesforce account, which the group claimed to have compromised as part of a wider campaign affecting dozens of companies, including Qantas, Gap, and Fujifilm. Vietnam Airlines' own internal IT systems were not affected, according to the company.
October 3, 2025: Hackread reported that Scattered LAPSUS$ Hunters claimed to have stolen records from 39 companies through Salesforce accounts and set an October 10 deadline for ransom negotiations.
October 10, 2025: The group published what it described as the Vietnam Airlines dataset on leak sites, alongside data from five other companies.
October 13, 2025: VNCERT, Vietnam's national computer emergency response team, confirmed to VietNamNet that Vietnam Airlines customer data was listed for sale on hacker forums.
October 14, 2025: Vietnam Airlines confirmed the breach in a press release and began notifying potentially affected customers by email.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, phone numbers, and dates of birth.
Vietnam Airlines' notice to customers, as reported by VnExpress International, additionally listed Lotusmiles frequent flyer membership numbers among the data that may have been exposed.
Not every individual is affected by every type of data listed here.
The airline stressed that credit card details, payment information, passwords, travel itineraries, passport numbers, and Lotusmiles account balances were not affected. The leaked records span a period from November 2020 to June 2025, according to VietnamNet.
What Are the Potential Risks for Affected Individuals?
Contact details and dates of birth are the raw material for targeted scams. With this data, criminals can send phishing emails or place calls that reference a person's real name and travel history, making the messages harder to dismiss. Vietnam Airlines itself warned customers to expect suspicious emails, calls, or messages impersonating the airline.
Knowledge of Lotusmiles membership numbers also raises the risk of account takeover attempts on frequent flyer accounts, where criminals may try to redeem miles or combine guessed passwords with leaked contact data. Because the airline's customers received legitimate-sounding follow-up emails about this very incident, attackers can also imitate breach notifications to trick people into handing over credentials or one-time passcodes.
What Is Vietnam Airlines Doing in Response?
In its October 14 statement, the airline said it was working with relevant authorities, cybersecurity experts, and its technology partner to investigate the breach, assess the impact, and strengthen data protection measures. It said customers whose information is potentially involved were being informed and offered available support.
The airline also published guidance: change your Lotusmiles account password and the password of any linked email account, stay alert to phishing attempts, avoid sharing personal information, OTP codes, or login credentials with unverified sources, and do not log into unverified systems. Vietnam Airlines set up a Data Protection Office contact at dpo@vietnamairlines.com and 24/7 hotlines, including 1900 1100 within Vietnam and +84 24 3832 0320 for calls from outside the country.
What Should You Do If You Were Affected?
If you are a Vietnam Airlines customer or Lotusmiles member, take these steps:
Change your Lotusmiles password and the password of any email address linked to the account, and enable two-factor authentication where it is offered.
Treat calls, texts, and emails claiming to come from Vietnam Airlines with suspicion, even if they cite your name or travel details. Verify through official channels before acting.
Never share OTP codes or login credentials with anyone, and avoid logging into unverified websites or apps.
Watch for follow-up phishing that references this breach itself, since attackers often impersonate breach notifications.
