BCD Travel USA LLC
ent_6ff23543739add09824cf48d
Disclosures
3
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,000
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BCD Travel USA LLC
- Normalized
- bcd travel usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- Massachusetts State AGas victim2023-08-18
BCD Travel USA LCC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-18. 77 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-08-14
BCD Travel USA LLC notified the New Hampshire Attorney General of a cybersecurity incident involving the MOVEit Transfer application. The breach exploited a zero-day vulnerability (CVE-2023-34362) exploited by the CL0P ransomware group. Unauthorized access occurred on May 29, 2023, and was discovered by BCD on June 1, 2023. The incident resulted in the exfiltration of personal information belonging to 17 New Hampshire residents. BCD engaged forensic experts, took the application offline, and began notifying affected individuals on August 11, 2023, offering one year of credit monitoring.
- Indiana State AGas victim2023-08-11
BCD Travel USA LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-29 and was reported on 2023-08-11. 15 Indiana residents were affected. 3,000 individuals affected in total.