Travala Pte. Ltd. reported a data security incident to the New Hampshire Attorney General on June 29, 2026. On June 18, 2026, an unauthorized third party accessed production databases using leaked developer credentials obtained via infostealer malware. The attacker exfiltrated customer personal data, including names, emails, addresses, passport numbers, and usernames, affecting one New Hampshire resident. The company revoked access keys, rotated credentials, isolated servers, and engaged external security specialists.