-
Travala, a crypto travel booking platform, confirms hackers accessed some customer records without permission.
-
The stolen data includes names, emails, and hashed passwords, but not crypto funds or wallet keys.
-
Travala has fixed its systems, but experts warn users to stay alert for scam emails.

Crypto companies keep facing the same problem. Their blockchain systems stay strong, but their regular databases stay weak. Travala, a travel booking platform built for crypto users, just learned this the hard way.
The company confirmed that hackers broke into part of its customer database. This news adds to a growing list of breaches hitting companies that serve crypto users.
Details of the Data Breach
Travala found unauthorized access to some customer records and shut it down fast. The company then secured its systems and alerted affected users right away. It also reported the incident to data protection authorities, as required by law.
According to Travala’s security update, hackers only reached text-based customer records. They did not touch any crypto assets or wallet credentials, the company said. You can read Travala’s full update here.
The stolen data reportedly includes customer names and email addresses. Phone numbers were exposed too, but only for customers who had shared one. Travala also admitted that hashed passwords were part of the leak. A hashed password looks like scrambled code instead of plain text. However, the company stressed that no plain, readable passwords were exposed.
A separate dark web claim involving Iranian travel agencies illustrates the global scale of the threat. The listing, which has not been independently verified, alleges 107 million records, including date of birth, gender, phone numbers, and passport numbers, showing that attackers are actively targeting booking platforms across different regions.
Other reports point to more sensitive details. These reports rely on breach notices filed with United States regulators. Some affected accounts may have had birth dates and nationality exposed too.
Passport numbers and national ID details might also be part of the leak, according to a report from NewsAffinity. Not every customer lost the same type of information. The exact details varied from person to person, based on what each account held.
Travala made one thing clear throughout its statement. The breach did not touch customer funds or wallet seed phrases. Private keys stayed untouched too, the company confirmed. Travala’s Concierge service and active two-factor authentication also remained safe. This matters a lot. It means hackers grabbed personal details, not actual crypto holdings.
Why this Breach Still Puts Users at Risk
Losing your name and email might sound small. But scammers can do a lot with just that. They can build fake emails that look real and trick people into clicking bad links. Since Travala serves crypto users, scammers could pretend to be the company itself. A fake email claiming to be from Travala could easily fool someone.
The hashed passwords raise more concern too. Hashing scrambles a password so hackers cannot read it directly. But how safe that scramble stays depends on the method used. Some hashing methods are stronger than others.
Travala said plain passwords were not exposed, and that lowers the risk. Still, users who reuse passwords across different sites face extra danger. If one account falls, others using the same password could fall too.
Interestingly, regulators appear to have known about this breach earlier than the public did. Massachusetts posted a breach notice tied to Travala Pte. Ltd. back in June 2026, according to the state’s public breach listing.
That means paperwork on this breach started months before Travala’s wider announcement on August 27. The delay between quiet regulatory filings and loud public news is common, but it still raises questions about timing.
Meanwhile, Travala’s crypto token, AVA, has stayed strong through all this. Reports say the token remains over 40% higher than where it started in August, according to posts shared on social media. But a rising token price says nothing about user safety. Token performance and account security are two completely separate issues, and one should never be mistaken for the other.
Steps Travala Took and What Users Should Do Now
Travala responded by tightening its security setup across the board. The company said it strengthened its infrastructure and locked down affected systems. It also brought in outside security experts to help investigate the incident, according to its official update. These steps aim to stop similar breaches from happening again.
Users should not wait around for more updates before acting. Change your Travala password now, especially if you used it elsewhere too. Turn on two-factor authentication if you have not already. Choose a fresh, unique password for every account you own online.
Watch your email closely over the next few weeks. Scammers often strike right after a breach becomes public news. Do not click links inside emails you did not expect to receive. If a message claims to be from Travala, check the sender’s address carefully first. When in doubt, visit Travala’s website directly instead of clicking any link.
Keep an eye on your other accounts too, especially ones sharing your Travala password. Watch for strange login attempts or unexpected password reset emails. Report anything unusual to the platform right away. Small warning signs often show up before bigger damage happens.
This breach shows a pattern that keeps repeating across crypto platforms. Blockchain tech can lock down digital assets pretty well. But regular servers holding names, emails, and passwords stay exposed to the same old tricks hackers have always used.
Crypto companies must protect both sides equally: the blockchain and the basic customer database, because attackers will always go for the weaker one.