Travala Data Breach Exposes Customer Details While AVA Stays Up 40%

By Onkar Singh // August 28, 2026 @ 09:17 AM Make AlphaWire Logo preferred on Google News

Share

More Markets Exploit Drains $9.3M in WFLOW as FLOW Drops 9%

Share

Points of Focus

  • A Travala breach exposed customer data, hashed passwords, and passport details.
  • Compromised developer credentials opened access to Travala’s AWS production environment.
  • AVA remains roughly 40% above its late-July price despite disclosure.

 

 

Crypto-friendly travel platform Travala has disclosed a customer data breach involving personal information, hashed passwords, and some identity-document details but said customer funds, private keys, and active two-factor authentication (2FA) credentials were not compromised.

The incident traces back to June 17, when an unauthorized third party gained access to Travala’s production environment using compromised developer credentials, according to breach notifications filed with US state regulators. Travala said it revoked the compromised access keys, blocked attacker infrastructure, and strengthened monitoring after discovering the intrusion.

Regulatory filings linked to the incident cover at least 2,305 affected individuals across the reported jurisdictions, although that figure should not be treated as Travala’s total global exposure.

 

 

The breach has so far had little visible impact on Travala’s AVA token. AVA traded around $0.209 on Aug. 27, roughly 39% above its July 29 close of $0.150. The token briefly reached $0.216 earlier in August before giving back part of the rally.

 

Passport numbers and hashed passwords were exposed

Travala’s notices say the exposed information varied by customer.

Potentially affected data included names, email and postal addresses, phone numbers, nationality, and dates of birth. Some records also contained passport numbers and expiry dates, usernames, hashed passwords, linked sign-in information, 2FA settings, and cryptocurrency wallet addresses.

The company has stressed that plaintext passwords were not exposed.

A customer notice shared publicly on Aug. 27 also said passport or national ID text details may have been included, but not scans or photographs of identity documents. Travala said active 2FA secrets, private keys, wallet seed phrases, and customer funds were unaffected.

That still leaves a meaningful phishing risk. A criminal holding a customer’s name, email, nationality, phone number, and passport details has considerably more material for building convincing fake support messages than someone working only from a leaked email address.

Travala has specifically warned users to be suspicious of unsolicited contacts that use personal information to establish trust.

 

Compromised developer credentials opened the production environment

The reported attack vector also separates this incident from a conventional wallet exploit.

According to the New Hampshire filing summarized by DisclosureLens, an attacker used compromised developer credentials through infostealer malware to enter Travala’s Amazon Web Services production environment and exfiltrate databases.

Travala responded by revoking affected AWS keys and rotating credentials. The company said forensic work did not identify persistent attacker access after containment.

The incident may also explain Travala’s increased security activity immediately afterward. On July 10, the company opened a public Security Response Center and bug bounty program covering Travala’s website, public APIs, and official mobile experiences.

Travala has not publicly disclosed whether that launch was directly prompted by the breach.

 

AVA’s rally has held despite the security disclosure

AVA fell as low as approximately $0.147 on July 29 but subsequently climbed above $0.21, putting it close to 40% above that late-July level. CoinGecko recently placed AVA’s market capitalization around $15.7 million, with roughly $7.4 million in daily trading volume.

The rally also predates the latest public attention around the breach, making it difficult to connect AVA’s performance directly to the incident.

Travala’s underlying business, meanwhile, has continued operating normally. The company reported more than $7.89 million in gross revenue for July, up from more than $7.43 million in June.

Its AVA loyalty program had 160,000 Smart members in July, up 116% year-on-year, while 9.98 million AVA, representing 13.42% of the circulating supply, was locked in the program.

For Travala, the immediate financial damage is limited compared with the privacy risk facing affected customers. Funds were not reported stolen, and operations remain online, but the combination of identity information, contact details, and account metadata gives attackers exactly the kind of material commonly used to build targeted crypto phishing campaigns.

 

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency prices are highly volatile. Always conduct your own research before making investment decisions.

 

Share

Default avatar

Onkar Singh

Onkar is a seasoned digital finance (DeFi) content creator with half a decade of experience in the blockchain and cryptocurrency industry. He has contributed to leading crypto media platforms, and collaborated with numerous DeFi projects worldwide. He blends his passion for technology and storytelling to deliver insightful content that bridges the gap between complex blockchain concepts and mainstream understanding.

Table of content

Ad

Related Articles