Skip to content

BCD Travel

Disclosed Jun 5, 20263 months ago396,313 accountsUnverified

In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.

What is known

People affected396,313 (accounts in the leaked data, per Have I Been Pwned)
DisclosedJun 5, 2026
HappenedMay 29, 2026
AttackExtortion
Data exposedEmails, Employment, Names, Phone numbers, Addresses
SectorHospitality
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: BCD Travelhaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataJun 5396,313
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about BCD Travel

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.