HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTAUTHENTICATIONMediumContained
Travala
bd_5cf40a13a5acd584 · schema v1 · pii pii-v1
Full breach record for Travala →Travala Pte. Ltd. reported a data security incident to the New Hampshire Attorney General on June 29, 2026. On June 18, 2026, an unauthorized third party accessed production databases using leaked developer credentials obtained via infostealer malware. The attacker exfiltrated customer personal data, including names, emails, addresses, passport numbers, and usernames, affecting one New Hampshire resident. The company revoked access keys, rotated credentials, isolated servers, and engaged external security specialists.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_fd012d8c39a179c5Vermont State AGfiled 2026-06-29Verified
- bd_120e7222fb9ed6a1Indiana State AGfiled 2026-07-05(6d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/travala-20260629.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2026
- Raw hash
- aaf5a4c04b8e5d2bd4d028ac791d1fdeb3272b7f5ae27a86b8e3735408d61c97
Reporting entity
- Name
- Travalanorm: travala
- Domain
- travala.com
Victim entity
- Name
- Travalanorm: travala
- Domain
- travala.com
Incident
- Discovered
- Jun 17, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1056 Input CaptureT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the relevant data protection authorities, including but not limited to the Personal Data Protection Commission in Singapore
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 days(11 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.