Ransomware victim disclosure
← All victimsBCD Travel
Claimed by shinyhunters · listed 5 days ago
Status timeline
- Listed
May 29, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- NL
- Sector
- Business Services
- Listed on leak site
- May 29, 2026
About the victim
AI dossier — public-source company profileBCD Travel is a global corporate travel management company. The company provides travel booking, expense management, and related services to business clients worldwide.
- Industry
- Business Travel & Expense Management
Attack summary
Severity: high — Confirmed exfiltration of large-scale business data (700k+ Salesforce records) and corporate files from a major travel services provider. Data appears to include customer and operational information. Threat actor published the claim with operational timeline, indicating intent to publish.ShinyHunters claims to have compromised over 700,000 Salesforce records and multiple SharePoint sites containing corporate data. The group threatens to publish the exfiltrated data and cause operational disruption if ransom is not paid by 1 June 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce records (700k+)
- SharePoint corporate data
- Customer/business information
What the group claims
Over 700k Salesforce records and various Sharepoint sites corporate data has been compromised. This is a final warning to reach out by 1 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 29 May 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
