On March 30, 2026, Sri Lankan travel agency NKAR Travels & Tours appeared on the leak site of the ransomware group known as Payload, with internal files reportedly exfiltrated during a ransomware attack. Customers who booked classical, cultural, wildlife, wedding, or luxury tours through the agency may have had personal details exposed, along with staff records and operational documents.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch NKAR Travels & Tours
Get alerted the next time NKAR Travels & Tours files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about NKAR Travels & Tours’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Payload listed NKAR Travel House after the company apparently declined or failed to meet the group's ransom demand. The data consists of internal files exfiltrated rather than a simple database dump. No precise victim count has been published, and the exact volume or sensitivity of the documents remains unclear from available screenshots on the leak portal. The incident follows the typical ransomware pattern of initial access, data theft, encryption, and subsequent public shaming when payment is not received.
Why This Matters for You and Your Family
If you or anyone in your household booked travel with NKAR, your names, contact details, passport information, itineraries, or payment records could now sit in an attacker-controlled archive. Travel agencies routinely store copies of passports, addresses, phone numbers, and email accounts, exactly the building blocks criminals need to open new accounts, request password resets, or impersonate you to banks and government offices. For families, a single breach can ripple outward: one parent's booking might link to children's names and dates of birth, giving attackers persistent hooks into your entire household.
The Doxxing and Identity-Chain Implications
Stolen travel records rarely stay isolated. A leaked email or phone number from this incident can be cross-referenced with gaming accounts, social-media handles, and data-broker profiles to build a complete identity chain. Once attackers map your username across platforms, they can pursue account takeovers, SIM-swapping, or full doxxing campaigns. Credential leaks like this one cascade into gaming-account takeovers when the same password was reused for a child's Roblox, Fortnite, or Steam profile tied to the family address. The chain often ends with extortion demands directed at the most vulnerable member of the household.