Inside the Explore Holidays India Database Breach: How 4,284 Accounts Were Exposed
In June 2022, Explore Holidays India, an online travel agency based in India, had its user database exfiltrated and leaked. The breach exposed 4,284 unique email addresses tied to usernames, phone numbers, and password hashes stored in both MD5 and bcrypt formats. The data was recieved by dark web actors and circulated through private channels, with the full underlying database estimated at approximately 41,000 records.
What Attackers Can Do With Stolen Travel Account Credentials
Travel accounts are accessable goldmines for fraudsters: they often contain booking histories, payment method references, phone numbers, and personally identifiable details that can be used to impersonate users or commit travel fraud. Attackers with access to these credentials can attempt credential stuffing against airline loyalty programs, hotel booking platforms, and payment processors. MD5-hashed passwords in particular are highly susceptible to offline cracking, meaning plaintext passwords may already be circulating.
What Was Exposed in the Explore Holidays India Breach
- Email Address
- Phone Number
- Password Hash (MD5 and bcrypt)
- Username
Why Mixed Password Hashing Creates Unequal Risk
The use of both MD5 and bcrypt in the same database is a red flag. It suggests the platform migrated to stronger hashing at some point but never retroactively upgraded legacy accounts. Users whose passwords were stored in MD5 are at significantly higher risk than those protected by bcrypt. This is partcularly concerning because affected users have no way of knowing which algorithm protected their account.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store, often through SQL injection, misconfigured cloud storage, or compromised admin credentials. The attacker exports user records in bulk, then sells or publishes the data on dark web forums. In the case of Explore Holidays India, the clean table structure of the dump points to direct database access rather than a web-layer scrape, suggesting the attacker had elevated privileges or exploited a backend vulnerability.
Check If Your Data Was Exposed
HEROIC's DarkWatch database contains over 400 billion exposed records, including data from breaches like Explore Holidays India. Search your email address now at HEROIC to find out if your credentials have been compromised and take action before attackers do.
Breach Breakdown
4,284 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds