Crypto-friendly travel platform says funds, private keys and wallet seed phrases were unaffected as it notifies regulators and members.
Online travel booking platform Travala.com has disclosed a data breach involving unauthorised external access to certain customer records, telling members that text-based profile information linked to their accounts was exposed. The company said it had identified and contained the incident, secured its systems and notified the relevant data protection authorities.
In a notice sent to affected users, the company operated by Singapore-based Travala Pte Ltd said the compromised information was limited to text-based data and that customer funds and platform operations were not affected. “Your funds are safe, individual accounts are uncompromised, and platform operations—including our Concierge environment—remain entirely unaffected,” the notice stated.

What was exposed
According to Travala, the affected records included profile and contact details such as email addresses and, where provided, phone numbers, names, dates of birth and nationality. Sign-in related data was also involved, including cryptographically hashed passwords — the company stressed that no plaintext passwords were exposed — and third-party sign-in preferences such as Google or Facebook logins.
The exposure also extended to identity document details, specifically passport or national ID text data such as document numbers and expiry dates. Travala emphasised that no scans or photo IDs were involved.
What was not affected
The company said that account funds, private keys and wallet seed phrases were never at risk, and that information tied to its Concierge clients remained confidential. Passwords remain securely encrypted and active two-factor authentication methods, including Google Authenticator and phone verification, were unaffected, Travala said.
Regulatory notifications and response
Travala said it had fully secured its systems, strengthened its infrastructure and taken the required regulatory steps following the incident. Breach notifications submitted to United States state authorities, including the New Hampshire and Massachusetts attorneys general, indicate the company also engaged external security specialists and notified Singapore’s Personal Data Protection Commission. The number of individuals affected was not disclosed in the customer notice.
The company urged members to review their security settings, refresh two-factor authentication and check linked sign-in accounts. It also warned users to be alert to phishing attempts, noting that Travala would never ask for passwords or private keys and that criminals may use exposed personal details to appear credible in unsolicited communications.
“We sincerely apologise for this occurrence and remain committed to protecting your data.” the company said, directing members with questions to its Data Protection Officer Travala.com.
















Comments