Vietnam Airlines data was published during the escalation in which Qantas records were leaked, part of the extortion campaign filed at 26-0625 and 26-0702.
The publication is the event here. The theft happened earlier, and in most cases had already been disclosed and notified.
Publication Is A Separate Phase With Its Own Timing
A theft-and-extortion operation acquires data, negotiates, and then either publishes or does not. That last decision can come months or years later, and it is made for reasons unrelated to the original victim — pressure on current negotiations, or a demonstration of resolve to future ones.
It means an organisation that handled an incident correctly, notified everyone, and closed the matter can find it reopened by a decision taken elsewhere, with no new intrusion.
The Affected People Are Told Once, If At All
This is the gap flagged in the Qantas file and it deserves repeating. Notification regimes fire on discovery of a breach. There is generally no obligation to tell people when previously stolen data is actually published — the moment their exposure changes from theoretical to concrete.
A passenger notified in one year that their details "may have been accessed" is not told the following year that the details are now downloadable.
Graded medium. The publication is consistently reported; the original incident scope for this carrier is not established in the material we reviewed.
Compiled from public reporting, listed below. We did not access the published data and do not describe its contents. Corrections: corrections@forensicpost.com.