
The cybercriminal extortion group ShinyHunters published the personal data of approximately 396,000 customers of BCD Travel, a Utrecht-based business travel management company, on the dark web after the firm failed to meet a June 1 ransom payment deadline.
BCD Travel, the travel division of BCD Group, which reported sales of $24.4 billion last year, provides trip planning and related services — including flight, hotel, and rental car bookings — to multinational corporations and government clients worldwide. The company acknowledged it had recently detected suspicious activity on an internal account and activated its security protocols, bringing in outside specialists to assess the scope of the incident. BCD said its services were not disrupted and that its IT systems remained operational, but it did not confirm the scale of the breach or disclose the ransom amount demanded.
ShinyHunters claimed to have exfiltrated more than 30 gigabytes of compressed data, allegedly including over 700,000 Salesforce customer-management records, internal SharePoint documents, customer files, contracts, and other operational data. After BCD Travel did not pay by the June 1 deadline, the group published the stolen material online.
Cybersecurity researcher Troy Hunt, who operates the data-breach notification service Have I Been Pwned, said the leak contained 396,313 unique email addresses, along with names, physical addresses, phone numbers, job titles, and customer support tickets. Hunt noted on social media platform X that 28 percent of the leaked email addresses were already in the Have I Been Pwned database from prior breaches.
ShinyHunters, which has been active for more than six years, specializes in data theft and extortion rather than locking victims out of their own systems — a tactic distinct from traditional ransomware. The group has claimed a series of recent victims, including Dutch telecom provider Odido, digital car marketplace CarGurus, the European Commission, student information system provider Infinite Campus, and Instructure, the company behind the Canvas education platform.
Odido publicly refused on multiple occasions to negotiate with or pay ShinyHunters, and its customer data was subsequently posted online. Instructure acknowledged paying the group and said the stolen data had been deleted as a result. ShinyHunters’ attack on Odido in February was described as the largest data breach in Dutch history, exposing personal information belonging to more than six million current and former customers after an employee was reportedly tricked into submitting login credentials through a fraudulent website.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543