HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Travelopia Group Holdings Limited
bd_8e632ce7820f0acb · schema v1 · pii pii-v1
Full breach record for Travelopia Group Holdings Limited →Travelopia Holdings Limited, a UK experiential travel company, notified the New Hampshire Attorney General of a data security incident. Unauthorized access to files occurred on or about October 2-3, 2025, discovered by the company on October 3, 2025. The investigation confirmed that personal information of 2 New Hampshire residents, including names combined with Social Security numbers or driver's license numbers, was accessed. Notification letters were sent on April 8, 2026, offering 24 months of credit monitoring and identity protection services through Kroll.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6d2c3072415850d4Massachusetts State AGfiled 2026-05-01(12d gap)Verified by operator
- bd_e94c752bffcc59c4Indiana State AGfiled 2026-04-08(35d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/travelopia-holdings-limited-20260513.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 13, 2026
- Raw hash
- b331258a53d028b094fa215c92d0c949272c750e5b029945480a15fc47d5fe54
Reporting entity
- Name
- Travelopia Group Holdings Limitednorm: travelopia group
Victim entity
- Name
- Travelopia Group Holdings Limitednorm: travelopia group
Incident
- Discovered
- Oct 3, 2025
- Materiality determined
- —
- Notification sent
- Apr 8, 2026
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
Compliance
- Time to disclose
- 32 weeks(222 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.