BCD Travel Data Breach: 396,000 Records Exposed in ShinyHunters Extortion Campaign
Summary
In May 2026, corporate travel management company BCD Travel was targeted by the ShinyHunters "pay or leak" extortion campaign. Data allegedly stolen from BCD was published publicly in early June, exposing 396,000 unique email addresses along with names, addresses, phone numbers, job titles, and employer names across multiple data sets including leads, internal staff, and support tickets. The article also promotes password managers and identity theft protection services as recommended actions for those affected.
Source
Key quotes
· 3 pulledIn May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters 'pay or leak' extortion campaign.
Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses.
Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.
You might also wanna read
Google Confirms Data Breach in Salesforce CRM Theft Campaign by ShinyHunters
Google has become the latest victim of a data breach in a series of Salesforce CRM data theft attacks orchestrated by the ShinyHunters extor
PornHub Premium Member Data Stolen in Mixpanel Breach, Extortion Attempt by ShinyHunters
PornHub is being extorted by the ShinyHunters gang after hackers stole Premium member search and watch history data through a breach at anal
ShinyHunters defaces school Canvas login pages after Instructure data breach
Education tech company Instructure disclosed a data breach where hackers stole student names, emails, and teacher-student messages. The cybe

Qantas Customer Data Leaked After Hackers' Ransom Deadline Passes
Hackers from the collective Scattered Lapsus$ Hunters have leaked personal records of 5 million Qantas customers on the dark web after a ran
Checkout.com Responds to Cyber Extortion Attempt Targeting Legacy System
Checkout.com experienced a cyber extortion attempt by the criminal group 'ShinyHunters' who gained unauthorized access to a legacy third-par
checkout.com·7mo ago
Vercel Cloud Platform Hacked via Compromised Third-Party AI Tool
Vercel, a major cloud development platform, was hacked by the ShinyHunters group, who stole employee data including names, email addresses,

Comments
Sign in to join the conversation.
No comments yet. Be the first.