// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
ColdRecon / Breach Radar / BCD Travel
Breach Record

BCD Travel

DISCLOSED 2026-05-29 · STOLEN CREDS · 396,313 RECORDS EXPOSED

In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a...

The record

What we know

Disclosed
2026-05-29
Attack vector
Stolen Creds
Records exposed
396,313
Domain
bcdtravel.com
Data classes exposed
Email addressesEmployersJob titlesNamesPhone numbersPhysical addressesSupport tickets
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the BCD Travel disclosure. It updates if new public reporting emerges. All tracked breaches →

BCD Travel just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →