[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2aa4soqn8j6av":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":28,"seoTitle":14,"seoTitleEn":29,"seoDescription":14,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488253b2","terravision","Terravision Data Breach","terravision.eu","2023-02-01T00:00:00.000Z","2023-04-23T03:50:37.000Z","2026-07-18T23:59:17.442Z","Third party breach","",[],2075625,"known",null,"unknown","Critical",[22,23,24,25,26,27],"Dates of birth","Email addresses","Geographic locations","Names","Passwords","Phone numbers","\u003Cp>The Terravision data breach is a security incident recorded in February 2023, affecting approximately 2.08 million accounts. In the incident related to the European airport transfer service, customer contact information, date of birth, country, and password fields were exposed. This content has been prepared so that users can understand the scope of the incident, the exposed areas, the level of risk, and the steps to take, all on a single page.\u003C\u002Fp>\u003Cp>Travel data is considered sensitive along with phone and password fields because it can be linked to a person's travel plans and country information. The statement only includes verifiable data classes; different services with the same name, additional claims whose technical details are unclear, or information whose scope is unproven are not presented as a data field. This approach makes the real risk visible without misleading the user.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are: birth dates, email addresses, geographic locations, names, passwords, and phone numbers. The travel context can increase the credibility of fake transfer, reservation, ticket, refund, and destination messages. When these areas are used together, they can lead to outcomes such as account takeover, social engineering, fraud, physical targeting, or privacy violations.\u003C\u002Fp>\u003Cp>It is understood that passwords are associated with salted hash values; nevertheless, if the same password has been used for another travel or email account, it should be changed. Using the same or similar password on other services is one of the most critical risks in records containing passwords. In records that do not contain passwords, areas such as device, location, phone, address, education, job application, or financial context can make targeted messages more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 2.08 million customer records associated with the domain terravision.eu. The incident is classified as a confirmed record. In the scope assessment, the number of accounts, domain, sector, country, and data classes were checked separately. The data fields shown to the user were limited to the fields actually listed in the record.\u003C\u002Fp>\u003Cp>The sector has been corrected as an airport transfer and travel service, not something else. This distinction is particularly important for similar brand names, registrations covering multiple services, or sensitive sectors. The registration has not been combined with another event, expanded in a way that would create duplicate records, and the company context has been clarified as much as possible.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Terravision customers, people who make travel reservations, and users who use the same phone\u002Femail combination on other travel accounts are at risk. The main risk for these individuals is the matching of leaked fields with common information used on other accounts. When the same email address, phone number, username, device ID, or password is repeated, attackers may try this information on different services.\u003C\u002Fp>\u003Cp>Travel context can be abused in fake transfer reservations, delay notifications, refund, or route change messages. For corporate users, business email and task information stand out, while for individual users, address, date of birth, purchase, location, or membership context stands out. In fields such as education, telecommunications, finance, travel, politics, job applications, and VPN, the context itself can also increase targeting risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change their passwords and check the security of the phone and email registered in their travel accounts. If a password or password-like field is listed, users should change it on all accounts where they use the same password, use a unique password, and enable multi-factor authentication wherever possible. Taking action on only one platform may not be sufficient.\u003C\u002Fp>\u003Cp>If there are fields such as phone, address, date of birth, device ID, official ID, job application, or reward balance, users should check account recovery information, registered sessions, email forwarding, and suspicious messages. For institutions, processes should be updated against employee alerts, fake invoices, and account verification attempts.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In travel accounts, a unique password, the deletion of unnecessary personal data, and the verification of booking messages are important. In the long term, a password manager, unique password, multi-factor authentication, closure of old accounts, deletion of unnecessary profile fields, and data minimization form the basic security line. Since permanent personal data cannot be recovered, it relies on strengthening defensive account behavior.\u003C\u002Fp>\u003Cp>On the company and institutional side, post-incident inventory, access permissions, storage of old data, notification processes, and the use of third-party platforms should be reconsidered. On the user side, avoiding the repetition of the same identity information across different services and the habit of verifying suspicious communications through a secondary channel provide lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should check the travel, email, and payment accounts where they use the same password. If a match is observed, the user should first read which data fields are listed, and then prioritize the steps according to these fields. If there is a password, password change should be prioritized; if there is an official ID, ID monitoring should be prioritized; if there is location or device information, device security should be prioritized; if there is training or job application information, institutional account checks should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: This record is a sensitive customer data incident because it combines travel context, phone, date of birth, and password fields. The user should compare this record with their own account history; they should individually check services where they have used the same email, phone, username, or password. Unexpected call, message, email, or account recovery notification should be considered higher risk after the incident.\u003C\u002Fp>","Terravision Data Breach (2.1 Million Reported Records)","Terravision Data Breach. 2.1 Million reported records were reported. Reported data: Dates of birth, Email addresses, Geographic locations. Review the scope…","\u002Fuploads\u002Flogo\u002Fterravision_eu.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Terravision","Airport Transfers \u002F Travel","Italy"]