Travala
ent_d759192828c6f729ff3a89a1
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,305
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Travala
- Normalized
- travala— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- travala.com
Disclosure history (5)newest first
- Indiana State AGas victim2026-07-05
Travala Pte Ltd reported a data breach to the Indiana Attorney General. The breach occurred on 2026-06-18 and was reported on 2026-07-05. 7 Indiana residents were affected. 2,305 individuals affected in total.
- Nebraska State AGas victim2026-07-05
Travala Pte. Ltd. notified Nebraska residents in July 2026 of improper access to customer personal data. The incident involved names, contact info, passport details, and hashed credentials. The company contained the incident, secured systems, and engaged external specialists. No evidence of fund theft or unauthorized changes was found.
- New Hampshire State AGas victim2026-06-29
Travala Pte. Ltd. notified the NH Attorney General of a data breach affecting one New Hampshire resident. On June 18, 2026, an unauthorized third party accessed Travala's production environment using compromised developer credentials leaked via infostealer malware. The attacker exfiltrated production databases containing customer personal data, including names, email addresses, postal addresses, nationality, dates of birth, telephone numbers, passport numbers, and usernames. Passwords were hashed. The company contained the incident by revoking access keys, blocking attacker IPs, and rotating credentials. Forensic review confirmed the scope on June 25, 2026. Notices are being sent to affected residents.
- Massachusetts State AGas victim2026-06-29
Travala Pte. Ltd. notified Massachusetts residents of a security incident involving improper access to customer personal data. Affected data included names, contact details, passport numbers, and hashed credentials. The incident was contained, systems were secured, and authorities were notified. No seed phrases or direct fund access was compromised.
- Vermont State AGas victim2026-06-29
Travala Pte. Ltd. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-06-29. The reporting organization type is Other Commercial. 1 Vermont residents were affected. Categories of data breached: Government ID Numbers.