BREACHhibp29 May 2026

Breach: BCD Travel (396,313 accounts) — Email addresses, Employers, Job titles

BREACH. Sourced from hibp, summarised by Matproof.

AI Analysis

What changed and what to do.

On 29 May 2026, a data breach affecting BCD Travel was published on Have I Been Pwned, exposing 396,313 accounts. The compromised data includes email addresses, employer names, and job titles. This incident falls under the BREACH framework, indicating a confirmed security event with verified data exposure.

The breach primarily impacts BCD Travel, a global corporate travel management firm, and its clients across multiple sectors, including finance, technology, pharmaceuticals, and professional services. Any organization that used BCD Travel for corporate travel booking may have employee data exposed. This raises significant data protection concerns under GDPR and similar regulations, as the leaked information could facilitate targeted phishing or social engineering attacks.

Compliance teams should immediately verify whether their organization’s employees are among the affected accounts by cross-referencing email domains with the breach data. They must assess whether BCD Travel was a data processor under their GDPR Article 28 agreements and, if so, notify the relevant supervisory authority within 72 hours if a high risk to individuals’ rights is identified. Additionally, teams should instruct affected employees to reset passwords, enable multi-factor authentication, and remain vigilant against suspicious communications. A review of vendor risk management processes and contractual data protection clauses is also advisable.

View original at hibp

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More BREACH updates

Latest in BREACH.

← Back to all updates
Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.

Book a DemoBrowse all updates
Breach: BCD Travel (396,313 accounts) — Email addresses, … — BREACH | Matproof