BCD Travel data breach: ShinyHunters leaked the data after the ransom deadline passed
TL;DR
Corporate travel management company BCD Travel, based in Utrecht, was hit by the extortion group ShinyHunters in late May 2026. The group claimed more than 30 gigabytes and over 700,000 Salesforce records, set a 1 June pay-or-leak deadline, and published the data on the dark web when it was not paid. Have I Been Pwned verified 396,313 unique email addresses, along with names, physical addresses, phone numbers, job titles, and support tickets. BCD confirmed suspicious activity on an internal account and said its services were not disrupted.
Incident Response PlaybookExpand
- Confirm what the attacker actually holds. Separate verified data, such as what appears in Have I Been Pwned, from the group's own claims.
- Identify the source system. If a cloud CRM like Salesforce or a SharePoint site was the source, review its access logs and connected apps.
- Revoke and rotate. Reset credentials, kill active sessions, and remove suspicious OAuth or connected-app authorisations tied to the abused account.
- Enforce phishing-resistant MFA on the affected platform and on every account that can approve access.
- Preserve evidence before cleanup: authentication logs, data-export records, and the extortion communications.
- Establish scope and dwell time through structured forensic review. Determine when access began and what was exported.
- Notify legal counsel and your insurer. Route any contact with the attacker through specialist counsel.
- Where personal data is involved, notify the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours, and inform affected individuals.
- Notify law enforcement (politie, Team Cybercrime) and the NCSC where it applies.
- Because the data is public, assume no deletion. Warn customers and staff that the leak fuels targeted, personalised fraud.
- Brief your service desk and travel desk to expect impersonation referencing real bookings and ticket history.
- Monitor dark web sources for your organisation's exposed data and for reuse of the leaked identifiers.
Why stolen travel data is worth more than an email list
The BCD Travel data breach is a good example of why the value of stolen data depends on what it describes, not just how many rows it fills. In late May 2026 the extortion group ShinyHunters claimed it had taken more than 30 gigabytes from BCD Travel, the Utrecht-based corporate travel management company that books flights, hotels, and meetings for large employers. A travel manager's database is not a generic contact list. It records who travels, where, when, and on whose account, which is exactly the information a fraudster needs to write a message that lands. When the ransom deadline passed and the data went public, that record of corporate movement stopped being a private business asset and became a permanent resource for anyone who wants it.
What happened
ShinyHunters claimed the attack on 29 May 2026 and set a deadline of 1 June: pay, or the data leaks. BCD did not pay, and in early June the files were published on the dark web. The group claimed more than 700,000 Salesforce records, along with internal SharePoint sites, contracts, and internal documents. BCD has been careful about what it confirms. According to DutchNews, the company said it had "recently spotted suspicious activity on an internal account" and brought in outside specialists to assess the scope. It stated that its services were not disrupted and its IT systems kept working normally, and it did not confirm the scale of the theft or the ransom demand.
The independent picture came later. On 5 June the breach was loaded into Have I Been Pwned, which put the number of unique email addresses at 396,313. That is the verified floor, separate from ShinyHunters' own claim of more than 700,000 records. The two numbers count different things, and the smaller one is the one that has been checked. BCD Group, the parent, reported sales of 24.4 billion dollars last year, which is part of why a database like this draws a group that specialises in extorting large organisations.
How the attack worked
ShinyHunters is not a ransomware crew in the classic sense. It steals data and extorts, without necessarily encrypting anything, and it has done so for more than six years against targets including Ticketmaster. The group's usual way in is people, not software. In its documented cases it has used social engineering and voice phishing to talk an employee into handing over access or approving a connected application, then pulled data straight out of cloud platforms like Salesforce.
That pattern matters here because the same group ran the February 2026 attack on the Dutch telecoms company Odido, described as the largest hack in Dutch history, where employees were tricked into revealing login credentials and the data of more than six million customers was exposed. ShinyHunters was also behind the breach of the Canvas learning platform through its parent Instructure, which we covered on this blog. BCD has not detailed how the intruder reached the internal account it flagged, so the initial access here is not confirmed. What stays consistent is the target: business data sitting in a cloud CRM, reached through a trusted account rather than a broken firewall.
Who is affected
The verified exposure covers 396,313 email addresses, and the fields alongside them are what make this breach dangerous. Have I Been Pwned lists names, physical addresses, phone numbers, job titles, employer names, and support tickets. That is a profile, not just a login. For a corporate travel firm, the people in that database are largely business travellers and the staff who book for them, which means the leak reaches into hundreds of client organisations, not only BCD itself.
The practical risk is targeted fraud. Someone holding a real name, a real employer, a job title, and a support-ticket history can impersonate a travel desk or a colleague with uncomfortable accuracy. "Your flight to Munich next week has been rebooked, confirm here" reads very differently when the sender already knows you travel. And because this was a pay-or-leak extortion and the data is now public, there is no deadline that resets and no negotiated deletion to wait for. The information is out, and it stays out.
What this means for your organisation
A few things to take from this, whether or not you have ever booked through BCD.
Your exposure is not only your own systems. If a supplier holds your employees' travel records, their breach becomes your fraud problem. Map which third parties hold data about your people and their movements, and treat a travel or booking vendor as a serious data processor, not a convenience.
The attack surface is your staff, not just your perimeter. ShinyHunters keeps succeeding because it targets the people who can approve access. Voice phishing and consent-screen abuse walk past most technical controls, so the defence is trained staff and tight limits on what any single account can reach inside a cloud platform.
Leaked data has no expiry. Once a pay-or-leak dataset is public, the useful response shifts from prevention to knowing what is out there and watching for how it gets used. Attackers combine leaks, so an address and a job title from this breach can be matched with a password from another.
That last point is where continuous monitoring earns its place. Knowing which of your organisation's credentials and records have surfaced on dark web sources, and being told when new ones appear, is what SecDesk's Threat Exposure Management is built to do. Once your data sits on the dark web, the question is no longer whether it leaked but what is exposed and what an attacker can do with it.
Talk to a senior responder about BCD Travel data breach: ShinyHunters leaked the data after the ransom deadline passed.
Schedule a response callNeed incident response?
- Two-hour SLA
- Dutch senior responders
