Data breach
BCD Travel
- Records
- 803,799
- Breach date
- 29 May 2026Estimated
- Added
- 5 June 2026
What was exposed
7 types of data · 2 put you at serious risk
- Names803,799
- Email addresses738,335
- Phone numbers232,222
- Street addresses42,712
- Dates of birth15,948
- Passport numbers586
- Social security numbers252
About this breach
BCD Travel, a Dutch-owned corporate travel management company, has been named as a victim in a data extortion campaign by the hacking group ShinyHunters. Our investigation team estimates the breach involved about 803,799 rows of data, with an estimated attack date of May 29, 2026. According to reporting by DutchNews.nl, ShinyHunters claims to have stolen the data of roughly 700,000 customers and has published a file of more than 30 gigabytes online. The group says it reached a customer database running on Salesforce as well as internal SharePoint sites used by staff to share documents. BCD Travel has not confirmed the scale of the attack or what ransom, if any, was demanded.
Breach Timeline
June 1, 2026: ShinyHunters' stated deadline for BCD Travel to enter negotiations passed. According to Tweakers, the company did not appear to pay.
June 3, 2026: BreachNews reported that ShinyHunters published the alleged BCD Travel data on its data leak site after the deadline passed. The outlet noted it had not independently verified the files.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, phone numbers, dates of birth, street addresses, passport numbers, and Social Security numbers. The email addresses and phone numbers account for the bulk of the records, while passport numbers and Social Security numbers appear in a much smaller share of the dataset.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Most of the exposed data is contact and identity information rather than passwords or payment details, but it can still be used against you. Names paired with email addresses and phone numbers make phishing and smishing attacks far more convincing, because a message that knows your details feels legitimate. Scammers may pose as BCD Travel, your employer's travel desk, an airline, or a booking agency to extract passwords or payment information.
Dates of birth and street addresses are common verification answers for banks, phone carriers, and other services. If criminals hold that data alongside your email, they can attempt account takeovers or impersonation. The small number of exposed passport numbers and Social Security numbers carries a more serious risk, since those identifiers are harder to change and can support identity fraud. Expect targeted scams in the weeks and months after the data circulates, and treat unexpected messages about travel bookings with caution.
What Is BCD Travel Doing in Response?
In a written statement reported by DutchNews.nl, BCD Travel said it had recently spotted suspicious activity on an internal account and had taken steps under its own security protocol, bringing in outside specialists to determine the scope of the breach. The company said its services had not been disrupted and its IT systems were working normally. It has not confirmed the scale of the attack or whether a ransom was demanded. BCD has not published a detailed public notice about affected individuals in the sources reviewed for this article.
What Should You Do If You Were Affected?
Be alert for phishing emails, texts, and calls that reference travel bookings, your employer, or BCD Travel. Do not click links or share credentials in unexpected messages.
Turn on two-factor authentication for your email, banking, and travel-related accounts. Even without exposed passwords, a second factor blocks most account takeover attempts.
Change passwords on accounts that reuse a password you used with BCD Travel or its booking systems, and use a password manager to keep them unique.
Watch your financial statements and credit reports for unfamiliar activity. If your date of birth or address was exposed, consider a fraud alert or credit freeze with the major credit bureaus.
If your passport number or Social Security number appears in this breach, monitor those documents for misuse and report suspected identity theft to the relevant authorities promptly.
In the news
- DutchNews.nl: Dutch travel firm BCD hacked, 700,000 customers reportedly hitdutchnews.nl (opens in a new tab)
- BreachNews: ShinyHunters claims BCD Travel breach involving 700,000 Salesforce recordsbreachnews.com (opens in a new tab)
- Tweakers: ShinyHunters zet data van 700.000 klanten Nederlands reisbureau BCD op darkwebtweakers.net (opens in a new tab)
