BCD Travel, a corporate travel management firm, experienced a direct cyberattack by the ShinyHunters group in 2026. The incident was confirmed via third-party reporting, including BlackFog and Have I Been Pwned.
The breach exposed names, email addresses, phone numbers, physical addresses, job titles, employer names, and customer support tickets. Approximately 396,313 unique email addresses were affected. There is no indication that SSNs, medical data, or financial payment cards were part of the exposed data.
Details regarding official notification letters, regulatory filings, or class-action lawsuits are not publicly available in the provided sources. No specific U.S. states were explicitly listed as affected, though BCD Travel has U.S. operations.