CTS Journey Holdings, LLC
ent_7e9304e106d72e4743eee391
Disclosures
8
State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
37,682
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CTS Journey Holdings, LLC
- Normalized
- cts journey— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- New Hampshire State AGas victim2026-08-10
CTS Journey Holdings (dba Corporate Travel Service) notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately 8 NH residents. Unauthorized access occurred between Dec 3-11, 2025; discovered July 2, 2026. Compromised data included names, SSNs, and financial account/credit card numbers. CTS engaged forensic investigators, contained the threat, and offered 1-year credit monitoring to affected individuals.
- Vermont State AGas victim2026-08-04
CTS Journey Holdings, LLC d/b/a Corporate Travel Service reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-08-04. The reporting organization type is Other Commercial. 37 Vermont residents were affected. Categories of data breached: Social Security Numbers, Government ID Numbers, Financial Account Codes, Credit and Debit Account Info.
- Texas State AGas victim2026-08-04
CTS Journey Holdings, LLC, a Delaware limited liability company (DBA Corporate Travel Service) based in Northfield, Michigan, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-07-02 and reported on 2026-08-04. 564 Texas residents were affected. 37,682 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information. Consumers were notified via U.S. Mail.
- California State AGas victim2026-08-03
CTS Journey Holdings, LLC (DBA Corporate Travel Service) notified the California Attorney General of a cybersecurity incident where an unauthorized actor accessed its network between December 3, 2025, and December 11, 2025. The company discovered the compromise on July 2, 2026, after forensic investigation. Affected data includes full names. The company contained the threat, engaged external cybersecurity professionals, and is offering credit monitoring and fraud assistance services to impacted individuals.
- Nebraska State AGas victim2026-08-03
CTS Journey Holdings (DBA Corporate Travel Service) disclosed a cybersecurity incident where an unauthorized actor accessed its network. The breach occurred between December 3 and December 11, 2025, and was discovered on July 2, 2026. The incident involved the unauthorized access to personal information, specifically full names. CTS offered complimentary credit monitoring and fraud assistance to affected individuals. The filing covers residents from multiple states, including Nebraska, Rhode Island, and others.
- Washington State AGas victim2026-08-03
CTS Journey Holdings (DBA Corporate Travel Service) disclosed a ransomware incident affecting Washington residents. Unauthorized access occurred between Dec 3-11, 2025; discovered July 2, 2026. 2,226 individuals affected. Full names and likely other PII were exposed. Remediation includes credit monitoring and fraud assistance.
- Oregon State AGas victim2026-08-03
CTS Journey Holdings, LLC, a Delaware limited liability company (DBA Corporate Travel Service) reported a data breach to the Oregon Attorney General. The breach was reported on 2026-08-03. The breach occurred during 12/3/2025 - 12/11/2025. The breach was discovered on 12/11/2025. 37,682 individuals were affected. Notice was sent on 8/3/2026.
- Massachusetts State AGas victim2026-08-01
CTS Journey Holdings (DBA Corporate Travel Service) disclosed a cybersecurity incident where an unauthorized actor gained access to its network. The breach was discovered on July 2, 2026, following a forensic investigation. The incident compromised the full names of affected individuals. CTS contained the threat, engaged external cybersecurity professionals, and is offering complimentary credit monitoring and fraud assistance to affected individuals.