Last updated 1 month ago
BCD Travel, a corporate travel management company headquartered in the Netherlands, was breached as part of the ShinyHunters 'pay or leak' extortion campaign. The incident was disclosed in early June 2026 after the threat actor published the stolen data publicly. The breach exposed 396,313 unique email addresses along with associated personal and professional information.
The attack vector involved unauthorized access to BCD Travel's systems, though the specific initial access method has not been disclosed. The exposed data sets included leads, internal staff records, and support tickets, containing names, addresses, phone numbers, job titles, and employer names. ShinyHunters, a known threat actor group, claimed responsibility and published the data after an extortion attempt.
No further post-incident details have been confirmed, including any regulatory notifications, litigation, or ransom payments. The breach notification status and remediation milestones remain undisclosed.
Extortion campaign by ShinyHunters; data published after extortion attempt
BCD Travel's breach underscores the need for robust access controls and monitoring to detect unauthorized access early, especially for organizations handling sensitive corporate travel data. The exposure of diverse data sets (leads, staff, support tickets) suggests inadequate data segmentation and least-privilege principles. Implementing strict data classification and encryption for personally identifiable information (PII) could mitigate the impact of similar extortion-driven breaches.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor