HackingIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
Travala
bd_b9824bf99283e428 · schema v1 · pii pii-v1
Full breach record for Travala →Travala Pte. Ltd. notified Massachusetts residents of a security incident involving improper access to customer personal data. Affected data included names, contact details, passport numbers, and hashed credentials. The incident was contained, systems were secured, and authorities were notified. No seed phrases or direct fund access was compromised.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1053-travala-pte-ltd/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- e0acd0f7a8115036a20ebca6de9f6a64b176ed347eab613b031c2d049a70acdb
Reporting entity
- Name
- Travalanorm: travala
- Domain
- travala.com
Victim entity
- Name
- Travalanorm: travala
- Domain
- travala.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the relevant data protection authorities, including but not limited to the Personal Data Protection Commission in Singapore
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.