Our Analysts Found the Barcelona Experts Customer Data Circulating After a September 2024 Breach
Our analysts flagged a data exposure tied to Barcelona Experts, a Spain-based travel and tourism agency that helps visitors plan trips to Barcelona. The breach was discovered on September 26, 2024, when customer records appeared on dark web monitoring channels. The data includes personal contact information for individuals who had booked or inquired through the agency's platform -- people who trusted a travel company with their details and had no reason to expect them to surface online.
Why This Is Dangerous
Barcelona Experts operates barcelonaexperts.com, providing travel planning and tour services across Barcelona. The September 2024 database breach exposed 126 confirmed records containing direct contact and identity information. While the record count is smaller than many breaches, the travel sector context amplifies the risk: people who book travel share real names, phone numbers, and email addresses that are verifiable and current -- making them high-quality targets for fraud.
Travel customers are also prime targets for follow-up scams. Attackers can impersonate the agency, a hotel, or an airline and contact victims about fake booking changes, refund requests, or itinerary updates -- all personalized using the stolen data.
What Was Exposed
- Email addresses -- primary contact channel for travel confirmation and phishing
- Phone numbers -- used for SMS fraud and voice impersonation scams
- First names and last names -- enables convincing, personalized social engineering
Why This Matters
Even a small breach in the travel sector carries outsized risk. Threat actors use travel-related personal data in targeted ways:
- Phishing: Victims receive emails that appear to come from the travel agency, a partner hotel, or a payment processor, using their real name and booking context to appear legitimate.
- Account takeover: Email addresses are tested against airline loyalty programs, hotel booking platforms, and other travel services where victims likely hold accounts.
- Identity theft: Name, email, and phone in combination are the building blocks of broader identity fraud, particularly when linked to a travel profile that may indicate financial means.
- Fraud: Phone numbers are used to call victims directly, impersonating the agency and requesting payment card details to "confirm" a booking.
How a Database Breach Works
Database breaches at small travel agencies typically result from unpatched web application vulnerabilities, weak or reused admin passwords, or inadequately secured customer relationship management (CRM) systems. Smaller businesses often lack dedicated security teams, making them attractive targets -- the reward for an attacker is the same (real personal data), while the defenses are usually weaker than those at a large enterprise. Once the attacker gains access, customer records are exported quickly and quietly. The company may not detect the incident for months, if ever.
Check If You Are Affected
HEROIC monitors thousands of breach sources and maintains a database of over 400 billion compromised records. If your email address appeared in the Barcelona Experts leak or any other breach, a free search will tell you instantly.
Breach Breakdown
126 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds