2026 Corporate Travel Service — network access Dec 3–11 2025; SSNs/IDs (≥656 state notices)
Data compromised
Full names, Social Security numbers, driver’s license / state ID / passport numbers, credit or debit card numbers, financial account information, and medical information (ClaimDepot / notice summaries; varies by individual)
Technical writeup
Verified multi-state consumer notices — CTS Journey Holdings LLC d/b/a Corporate Travel Service (Northville, MI) disclosed unauthorized network access between December 3 and December 11, 2025. After forensics and document review, the company determined on July 2, 2026 that impacted systems contained personal information. California AG sample notice filed August 3, 2026; Massachusetts OCABR packet and ClaimDepot (Aug 4, 2026) summarize Texas (~564), Massachusetts (~55), and Vermont (~37) resident tallies. recordsAffected 656 is the sum of those published state floors; nationwide total not disclosed. Complimentary credit monitoring offered; response line 1-866-898-5010. Small/mid verified travel-sector notice; no blog.
Root cause
Unauthorized actor accessed network environment Dec 3–11, 2025; personal data confirmed in impacted systems July 2, 2026 (CA AG / MA / TX / VT notices)