[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1o35a1of1rbwj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":34,"seoTitle":35,"seoDescription":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a452308a20f867c8ba8e705","vietnam-airlines","Vietnam Airlines Data Breach","vietnamairlines.com","2025-06-20T00:00:00.000Z","2025-10-11T09:20:39.000Z",null,"2025-10-12T01:28:16.000Z","2026-07-19T00:02:15.076Z","Third party breach","",[],7316915,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"Critical",[29,30,31,32,33],"Dates of birth","Email addresses","Loyalty program details","Names","Phone numbers","\u003Cp>The Vietnam Airlines data breach is a security incident recorded in the period of June 2025, affecting approximately 7.32 million accounts. Customer data associated with the Vietnam-based airline company was exposed in areas including the loyalty program and communications. This statement has been prepared to clarify which of the user's data may be at risk and which steps should be taken first.\u003C\u002Fp>\u003Cp>In the context of airlines and loyalty programs, fields such as date of birth, phone number, and membership number are valuable for travel fraud. The text only uses data classes that can be verified; unverified passwords, payment information, identification, or technical claims are not added as data fields. Events with similar names and different years belonging to the same brand are not confused with each other.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: birth dates, email addresses, loyalty program information, names, and phone numbers. Loyalty membership numbers and phone information can make fake flight, points redemption, upgrades, or booking messages appear credible. The presence of these fields together can make it easier for attackers to prepare fake account notifications, fraud, identity linking, or targeted social engineering attempts.\u003C\u002Fp>\u003Cp>This record does not list a password, payment card, or passport number; the risk focuses on loyalty programs and customer communication areas. Even if there is no password, the risk is not completely eliminated; address, phone number, date of birth, device information, business profile, loyalty program, web activity, or purchase information may also be sufficient to target the user. If there is a password, it should be urgently checked whether the same password is repeated on other services.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 7.32 million unique email addresses associated with the vietnamairlines.com domain. The incident is in the verified record category. The scope was determined by comparing the domain, company context, country, industry, account count, and data classes. The fields displayed to the user are limited to the fields listed in the record.\u003C\u002Fp>\u003Cp>The sector has been corrected to not other but airline and loyalty program, and the country to Vietnam. In some cases, company verification may be limited or the data set may have been spread in third-party environments. In this case, the explanation focuses on areas that show the user's real risk, without exaggerating uncertain points.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Vietnam Airlines customers, loyalty program members, and passengers whose phone\u002Fbirth date fields were exposed are at risk. The primary risk for these users is that the leaked fields can be matched with common information used on other platforms. If the same email, phone number, username, address, social profile, or password is repeated across different accounts, the attack surface increases.\u003C\u002Fp>\u003Cp>The airline context can be used in fake reservations, check-ins, point usage, flight changes, or identity verification messages. Gaming, retail, payment, social profile, travel, investment, airline, and health-wellness contexts generate different risks. The user should consider not only the list of domains but also which account or service those domains are associated with.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should verify their loyalty program accounts, point transactions, and flight notifications received by phone through official channels. If a password or password-like field has been listed, users should change it on all accounts where they use the same or similar password, use a unique password, and enable multi-factor authentication wherever possible. The email account should also be protected.\u003C\u002Fp>\u003Cp>If there are fields such as address, phone number, date of birth, device, business profile, purchase or loyalty program, users should check account recovery options, session history, forwarding rules, and suspicious messages. Verification and document requests received in the context of finance, payment, or airlines should be confirmed through a second channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Strong authentication in airline accounts, loyalty point notifications, and reducing unnecessary profile information are important. In the long term, a password manager, unique password, multi-factor authentication, closing old accounts, and deleting unnecessary profile fields are the fundamental defense. Since permanent personal data cannot be retrieved, user behavior and account settings should be strengthened.\u003C\u002Fp>\u003Cp>Data minimization for institutions, the retention period of old customer records, forum and community account permissions, loyalty program fields, and incident reporting processes should be regularly audited. On the user side, not using the same identity information everywhere permanently reduces risk.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches with this record, they should check the airline account, loyalty membership, and email security settings. If a match is found, the user should read which data fields are listed and determine the course of action accordingly. If there is a password, changing the password is a priority; if there is an address or phone number, a fraud alert is a priority; if there is finance or payment information, account monitoring is a priority; if there is a social profile, a privacy check is a priority.\u003C\u002Fp>\u003Cp>Final assessment: Although this record does not contain a password, it is considered a sensitive travel data incident because it includes date of birth, phone, and loyalty program information. The user should compare this record with their own account history; they should separately check the services where they have used the same email, phone number, username, address, or password. Any suspicious calls, emails, messages, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","Vietnam Airlines Data Breach (7.3 Million Reported Records)","Vietnam Airlines Data Breach. 7.3 Million reported records are reported. Reported data: Dates of birth, Email addresses, Loyalty program details. Review the…","\u002Fuploads\u002Flogo\u002Fvietnamairlines_com.webp",false,{"name":40,"sector":41,"country":42,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"Vietnam Airlines","Airline \u002F Loyalty Program","Vietnam"]