Travala, a Singapore-based travel booking platform that accepts both conventional payments and cryptocurrency, has publicly addressed a cybersecurity incident involving unauthorized access to limited customer records.
In an operational update published in late August 2026, the company said it detected and contained external access to certain text-based personal data / information and emphasized that user funds, individual accounts, and core platform functions were not compromised.
According to Travala, the company continuously monitors its systems to ensure customer data is accessed only when required and in line with its security standards.
During that monitoring, it identified unauthorized external access to a subset of customer information. Once discovered, the activity was contained immediately.
Travala stated that it then secured the affected systems and brought in outside security specialists to reinforce its infrastructure.
The firm also said it completed the regulatory notifications required after the event.
The company stressed that the most sensitive elements of customer accounts were never exposed.
Seed phrases, private keys, and other credentials that could unlock funds or assets held in Travala accounts remained untouched.
Platform operations, including the Concierge environment used by some clients, continued without interruption.
Travala attributed the limited nature of the exposure to its existing security architecture, which it said confined the incident to text-based fields such as names, email addresses, and phone numbers.
The exact combination of records differed from user to user depending on information provided during account setup or booking.
Affected customers were contacted individually by email with details specific to their accounts.
Earlier regulatory filings provide additional context on how the incident began.
An unauthorized party gained access to Travala’s production environment in mid-June 2026 by using leaked credentials belonging to a developer.
Those credentials had been stolen through infostealer malware on an unmanaged personal device.
The attacker copied production databases containing customer personal data.
Travala reported that passwords were stored in hashed form and that it does not believe individual account logins were taken over.
After detection, the company revoked compromised access keys, removed attacker-created network paths, blocked associated IP addresses, rotated credentials and signing keys, isolated affected servers, and rebuilt systems from clean images.
Forensic work was preserved.
Data categories described in those notices included names, email and postal addresses, nationality, dates of birth, telephone numbers, passport numbers and expiry dates, usernames, linked single sign-on identifiers, two-factor authentication details, and, where present, wallet records.
Passport images themselves were not retained.
Regulatory submissions indicated relatively small numbers of residents in certain US states were among those whose records were reviewed.
Travala’s public update listed several immediate and ongoing actions: instant revocation of unauthorized access, a full audit and sanitization of environments, required regulatory filings, and an expansion of its long-term operational security resources.
The company advised users to review security settings, consider refreshing two-factor authentication, and remain alert to phishing.
It noted that Travala will never request passwords or private keys and that unsolicited messages using personal details should be treated with caution. The firm apologized to affected customers and said it would continue strengthening defenses to protect the integrity of its platform. Questions can be directed to Travala’s Data Protection Officer.