2026 Travala — unauthorized access; passports, hashed passwords, crypto wallet addresses
Data compromised
May include names, emails, addresses, phones, nationalities, DOB, passport numbers/expiry, usernames, hashed passwords, linked sign-in/2FA data, crypto wallet addresses (varied by person)
Technical writeup
Verified company/regulator notice — June–July 2026. Travala Pte. Ltd. (Travala.com crypto travel agency) disclosed that it detected improper access to and copying of customer personal data, contained the activity, strengthened monitoring, and engaged external cybersecurity specialists. Federman & Sherwood (July 1, 2026) summarized a Nebraska Attorney General filing describing potentially exposed names, emails, mailing addresses, nationalities, dates of birth, phone numbers, passport numbers and expiration dates, usernames, hashed passwords, linked sign-in service information, two-factor authentication details, and cryptocurrency wallet address information. Vermont AG received a related filing June 29, 2026 (public summaries cite small state-level counts). Travala had not published a single nationwide headcount in sources reviewed at indexing. recordsAffected 0 pending company census; companyConfirmed true.
Root cause
Improper access/copying of customer personal data; contained after discovery; Nebraska/Vermont AG filings Jun–Jul 2026