← Travala

2026 Travala — unauthorized access; passports, hashed passwords, crypto wallet addresses

2026 Unknown records affected Share on X

Data compromised

May include names, emails, addresses, phones, nationalities, DOB, passport numbers/expiry, usernames, hashed passwords, linked sign-in/2FA data, crypto wallet addresses (varied by person)

Technical writeup

Verified company/regulator notice — June–July 2026. Travala Pte. Ltd. (Travala.com crypto travel agency) disclosed that it detected improper access to and copying of customer personal data, contained the activity, strengthened monitoring, and engaged external cybersecurity specialists. Federman & Sherwood (July 1, 2026) summarized a Nebraska Attorney General filing describing potentially exposed names, emails, mailing addresses, nationalities, dates of birth, phone numbers, passport numbers and expiration dates, usernames, hashed passwords, linked sign-in service information, two-factor authentication details, and cryptocurrency wallet address information. Vermont AG received a related filing June 29, 2026 (public summaries cite small state-level counts). Travala had not published a single nationwide headcount in sources reviewed at indexing. recordsAffected 0 pending company census; companyConfirmed true.

Root cause

Improper access/copying of customer personal data; contained after discovery; Nebraska/Vermont AG filings Jun–Jul 2026

References