Notice to travelers regarding data security incident

Travelport recently identified that data of certain travelers contained in our ViewTrip system had been subject to unauthorized access. As soon as we became aware of the incident, we implemented containment measures and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have communicated with affected Travelport travel agency customers and travel providers.

Whilst there is no evidence that traveler personal data has been published, sold, or used for phishing or identity fraud purposes, we are publishing this notice to make travelers aware of the incident and what they can do to protect themselves. If you are unsure whether this notice applies to you, we ask that you please contact your travel agency.

What happened

Travelport became aware of unusual activity on the ViewTrip platform on 6 August 2026. Travelport then promptly implemented containment measures and deployed a fix on 7 August 2026. ViewTrip has since been safely restored to service following the implementation of enhanced security measures.

Travelport's forensic investigation confirmed that a limited set of ViewTrip passenger records were subject to unauthorized access, including data relating to individuals whose data was processed on Travelport's ViewTrip platform via our travel agency partners. An unauthorized third party accessed and potentially obtained certain booking-related information from the application.

The incident was limited to ViewTrip, which is used only as an itinerary-viewing tool, and did not involve any compromise of other Travelport systems, networks or environments. We are not aware of any unauthorized modification to any travel plans.

What information may have been affected

The impacted data elements are set out below. We note however that the specific data impact varies based on what information was uploaded to ViewTrip – not every individual will have each of the below data elements impacted:

  • passenger names as they appear on bookings;
  • reservation and booking reference (PNR) details;
  • travel provider reference numbers;
  • contact information such as email addresses or telephone numbers (in many cases these relate to travel agencies rather than individual travelers);
  • flight, hotel, car hire and rail itinerary information;
  • special service request codes (for example, accessibility requirements or dietary preferences); and
  • loyalty program card numbers

Please note that no identity numbers or passport numbers were affected, and payment card numbers were not stored or exposed in clear text. A significant portion of the affected data related to historical rather than upcoming travel. There is no evidence that traveler personal data has been published, sold, or used for phishing or identity fraud purposes.

What we have done

Upon discovering the incident, Travelport acted swiftly:

  • We promptly activated our incident response procedures, deployed technical measures and conducted a detailed investigation.
  • We implemented the necessary containment measures. The ViewTrip website was temporarily taken offline to allow additional security measures to be deployed and validated.
  • We communicated with affected Travelport travel agency customers and travel providers.
  • We engaged external cybersecurity specialists and legal counsel to support our investigation and remediation efforts.
  • A permanent fix and additional safeguards were deployed before the service was restored.
  • Affected PNR records have been disabled as a precaution on ViewTrip.
  • The incident has been reported to various data protection authorities.
  • Continued dark web monitoring.

What you can do

Travelport is not aware of any publication or sale of the data, or any instances of phishing or identity fraud in connection with this incident. However, we cannot exclude the risk that certain contact information, such as email addresses or phone numbers, could potentially be used for phishing purposes. We reiterate that we are not aware of any such phishing attempts, and the affected data did not include financial account credentials, security questions and answers or other authentication data that could facilitate highly targeted or convincing phishing attempts.

With attacks of this nature becoming increasingly common, it is more important than ever to remain vigilant against suspicious activity to protect yourself online and reduce the risk of phishing attacks. As always, we encourage travelers to continue to follow standard security recommendations. These include:

  • exercising caution when clicking on links contained in communications from unknown or uncertain sources;
  • being vigilant regarding suspicious phone calls or messages that reference your travel arrangements or ask you to verify personal details or make payments;
  • not providing personal or financial information in response to unexpected requests, even if they appear to come from a known travel provider;
  • monitoring your loyalty program accounts for any unusual activity; and
  • independently verifying the authenticity of any communication purporting to be from a travel provider by contacting them through their official website or published contact details.

Please note that Travelport will not contact you to request your passwords, PINs, or banking details in connection with this notification. Should you receive such a request, we recommend you do not respond.

Contact information

For questions related to your booking, please contact your travel agency. For any other questions, you may contact Travelport’s global privacy team at:  ViewtripPrivacy@travelport.com