The Top Cruise Deals Breach Happened in April. The Data Is Still Circulating.
HEROIC analysts identified a data breach affecting Top Cruise Deals, a U.S.-based platform where users compare cruise rates and find discounted packages, with data first leaked on April 26, 2025. The compromised database contained records for 25,889 users, including email addresses and IP addresses. The data was identified circulating on underground forums where it was offered to other threat actors before the incident received any public attention or company disclosure.
What Attackers Can Do With Email Addresses and IP Addresses
At first glance, a breach containing only email addresses and IP addresses might seem minor compared to breaches that expose passwords or financial details. That assumption is dangerous. Email addresses are the primary identifier attackers need to launch phishing campaigns, and knowing someone's IP address at the time they used a service tells a criminal which internet provider they use, what general region they are in, and what kind of device or network they were likely on.
This combination is frequently used in spear-phishing, where an attacker crafts a message that appears to come from the breached company, referencing the user's interaction with the platform. The goal is to trick the recipient into clicking a malicious link, handing over credentials, or authorizing a payment. Because the attacker already knows the target used Top Cruise Deals, the lure is immediatly more believable than a generic spam message.
What Was Exposed in the Top Cruise Deals Breach
- Email Address
- IP Address
No passwords were included in this breach. The data did include associated timestamps, indicating when each user's record was captured, which gives attackers additional context for crafting timely and convincing follow-up attacks.
Why This Matters for Travel Platform Users
The travel and leisure sector is a consistent target for data theft because users of booking and comparison platforms are often actively spending money, making them attractive marks for financial fraud. A confirmed email address tied to a travel platform tells an attacker that the target is likely to respond to messages about upcoming bookings, pricing changes, or special offers.
There is also a credential stuffing dimension. Attackers who have a list of confirmed email addresses from a travel platform will run those addresses against airline portals, hotel loyalty programs, and payment services to find accounts where the same login is reused. Even though no password was leaked here, the email list alone enables this kind of automated attack at scale. Users should also be aware that their data may be combined with records from sepperate breaches to build more complete profiles over time.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to the storage system where a platform keeps its user records. This can happen through a vulnerability in the web application, an exposed administrative interface without proper authentication, or a compromised account with database access privileges.
Once inside, the attacker can extract structured records silently. In smaller-scale breaches like this one, the extraction often happens quickly and goes undetected until the data appears in criminal marketplaces. The focused nature of the data pulled from Top Cruise Deals suggests a deliberate, targeted extraction of user contact and network information rather than a broad sweep of all available data. Companies often don't discover this type of breach until an external researcher or intelligence service spots the data in the wild, which is precisly what happened in this case.
Check If Your Information Was Exposed
HEROIC offers a free breach scanner that checks your email address against more than 400 billion records from confirmed data breaches, including this Top Cruise Deals incident. If you have ever used the platform to compare cruise deals, it takes less than a minute to check whether your email address was part of this leak.
Run a free check at HEROIC's breach scanner and find out if your contact details are already being used by attackers targeting travel platform users.
Breach Breakdown
25,889 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds