In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.
Sponsored
Use a password manager to generate and store strong, unique passwords for all your accounts. 1Password helps protect your data with industry-leading security.
Affected Accounts:
396.3 thousand
Breach Occurred:
May 2026
Added to HIBP:
5 Jun 2026
If you haven’t already changed the password affected by this breach, do so immediately on every account where it was used.
Wherever 2FA is supported, add an extra layer of security to your account.
Sponsored
Use a password manager to generate and store strong, unique passwords for all your accounts. 1Password helps protect your data with industry-leading security.