Teletext Holidays data breach exposes 212,000 customer call recordings

Truly Travels, trading as Teletext Holidays, formed out of the once-popular television information text service. It now advertises package holidays online and completes bookings over the phone.
Verdict discovered the files – which have since been removed – on an unsecured Amazon Web Services server. In total, there were 532,000 files. Of those, 212,000 were audio files from Teletext customers calling its India-based call centre.
The calls took place between the 10 April 2016 and 10 August 2016. They range from a few minutes to up to an hour and, based on accents, appears to involve UK customers. In recordings heard by Verdict, customers can be heard booking holidays, amending bookings, enquiring about trips and making complaints.
Details about each holiday, including flight time, location and cost, can also be heard. In conversations where a holiday is booked, customers also tell the Teletext Holidays employees partial card details. This includes the type of card, name on the card and expiry date.
Instead of saying their card number and three-digit security number, customers type them into the keypad – protecting the most serious financial information. In a very small number of calls, Verdict heard customers begin to say their card number out loud before the call centre operator interjects.
The names and dates of birth of accompanying passengers, such as partners and children, can also be heard.
Teletext Holidays removed all 532,000 files almost immediately after Verdict notified the company. In a statement, a Truly Travel spokesperson (trading as Teletext Holidays) spokesperson said:
“We are in the process of reporting the matter to the ICO, and we will fully comply with our wider legal obligations.
“The company is taking all appropriate steps to ensure that this situation does not occur in the future.”
Customers recorded while on hold
In some calls heard by Verdict, Teletext customers continued to be recorded while putting on hold, with Verdict hearing couples talking privately among themselves. In one, a mother can be heard trying to calm her crying children while she waits.
In another, a couple is placed on hold for several minutes, during which they discuss whether to go ahead with the booking, before whispering “I’m going to hang up”.
The files were stored in a data repository titled ‘speech analytics’. In addition to the audio files, Verdict discovered 9,000 VTT files – a format for providing captions to audio files.
The customer calls appear to have been recorded as part of a call centre analytics project. Verdict asked Teletext to confirm if the exposed data related to a project with Indian technology company Zen3, which Teletext Holidays said: “is not the case”.
In February 2016, Teletext Holidays implemented the natural language artificial intelligence analytics system to turn call centre conversations into text.
In the exposed data, approximately 9,000 phonecalls are accompanied with text transcripts, potentially making it easier for a malicious hacker to scrape for personal data.
Security implications of Teletext Holidays data breach
Personal data, such as email addresses and dates of birth, can prove valuable information for online criminals. It is common for malicious hackers to sell databases containing personal data on underground forums, where it can be merged with additional personal details to create a full identity profile. Data can then be used to carry out identity fraud, phishing or targeted email attacks.
Malcolm Taylor, director of cyber advisory at cybersecurity consultancy ITC Secure, described the Teletext Holidays data breach as “an intelligence feed for hackers”.
“Aside from the painfully obvious ‘please don’t store unencrypted data in unencrypted data stores and be at all surprised when it leaks’, this makes the point very well that the actual medium in which data is stored is irrelevant; the fact that these were voice files makes no difference to the value of the data to hackers,” he told Verdict.
“It all has a dollar value and is saleable online (and will be for sale already). It is also a treasure trove for anyone who wants to build more sophisticated and damaging attacks – it’s an intelligence feed for hackers; this simple leak could spawn many more and worse.”
Taylor added that it would be fairly simple for a criminal to extract data from the audio files, albeit making them slightly longer.
The Teletext Holidays data breach is the latest in a long string of security incidents involving unsecured servers, many of which are provided by Amazon Web Services. AWS, which is the world’s biggest cloud hosting provider with a 34% share of the market, gives businesses the choice to keep the data repositories, known as buckets, public or private.
In many high-profile cases, involving both AWS servers and alternatives, a company has simply forgotten to make the files private. Notable recent examples include a database containing the records of millions of Chinese jobseekers, another containing the details of subscription service MoviePass’ customers and a Honda database containing vital information relating to the company’s network security.
532,000 files were found on GrayhatWarfare, a website that enables users to search unsecured S3 buckets.
Teletext Holidays data breach: Does GDPR apply?
Although the General Data Protection Regulation (GDPR) was introduced two years after the data was initially stored online, the fact that it was still online post-GDPR means the company could be liable for breaching the newer data protection laws. Under GDPR, an organisation can be fined a maximum of 4% of annual global turnover for the mishandling of personal data.
In the year ending 2018, Truly Travel, trading as Teletext Holidays, reported 2018 turnover of £152m, putting the maximum possible fine under GDPR at £6.08m
As data controller, Teletext Holidays is responsible for the protection of its customers’ data. Robert Wassall, director of legal services at cybersecurity firm ThinkMarble, told Verdict that the breach was “serious” and that it was “very likely” that Teletext would receive a fine for the data breach, adding that any third party involved may also be made liable.
He cited the number of individuals affected, the length of time it was left online and the risk of identity fraud as key reasons for the company being likely to be fined.
“Call recording is likely to be seen as very privacy-intrusive,” he added.
Teletext Holidays took the files offline around 5 pm GMT on Thursday, less than two hours after Verdict notified the company. This prompt removal will likely work in Teletext’s favour in any subsequent investigation by the UK’s data regulator, the Information Commissioner’s Office (ICO), said Wassall.
“Ironically, this may affect Teletext themselves more than the hackers,” added Taylor.
“To begin making contact with their affected clients they will have to find their own way of extracting the details – and they will probably find that more difficult than do the attackers. 532,000 records is not the biggest of leaks, but that will be of no comfort to those individuals affected; this is not an insignificant breach. It will be very interesting to see how the ICO respond.”
source verdict
Industry: Cyber Security

Latest Jobs
-
- Senior SOC Analyst Level 3. Microsoft Security stack | Ability to achieve SC Clearance
- London
- To attract the right person
-
Job Title: Senior SOC Analyst Level 3. Microsoft Security stack | Ability to achieve SC Clearance Location: Hybrid remote | London / Berkshire Overview: Senior SOC Analyst Level 3 to join a specialist Managed Security Services business. You will be responsible for advanced threat hunting / triage, incident response etc with a strong focus on the Microsoft Security Stack. Key Responsibilities: Lead and resolve complex security incidents / escalations Conduct advanced threat hunting using the Microsoft Security Stack. Build, optimise and maintain workbooks, rules, analytics etc. Correlate data across Microsoft 365 Defender, Azure Defender and Sentinel. Perform root cause analysis and post-incident reporting. Aid in mentoring and upskilling Level 1 and 2 SOC analysts. Required Skills & Experience: The ability to achieve UK Security Clearance (SC) – existing clearance ideal. (Sorry no visa applications) Current experience working with a SOC environment Microsoft Sentinel: Development and tuning of custom analytic rules. Workbook creation and dashboarding. Automation using Playbooks and SOAR integration. Kusto Query Language (KQL): Writing complex, efficient queries for advanced threat hunting and detection. Correlating data across key tables (e.g., SignInLogs, SecurityEvent, OfficeActivity, DeviceEvents). Developing custom detection rules, optimising performance, and reducing false positives. Supporting Sentinel Workbooks, Alerts, and Playbooks through advanced KQL use. Deep understanding of incident response, threat intelligence and adversary techniques (MITRE ATT&CK framework). Strong knowledge of cloud and hybrid security, particularly within Azure. Additional Requirements: Must hold or be eligible to achieve a minimum of Security Clearance (SC) level. Nice to have certifications (e.g., SC-200, AZ-500, GIAC) are desirable. Strong problem-solving and analytical skills. Excellent communication for clear documentation and team collaboration. Please follow Wheaton’s Law.
-
- New Business Sales Hunter | Cyber Security (UK Based)
- London
- To attract the right person
-
New Business Sales Hunter needed | Cybersecurity (UK Based) Are you looking for uncapped commission, a fun and sociable team that drives success with no politics? If so...You must Be UK based - and able to achieve UK SC clearance. (sorry no visas) Have a demonstrable history of sales success in Cyber Security Follow Weatons law. The role: Seeking a proven New Business Sales Hunter to join an established, successful and expanding cyber security firm. New business focused - £1m GP year one target (ramped). Sell a blend of security services & professional services. Ideal experience selling some or all of the following Cyber strategy & risk management Managed detection & response (MDR) Penetration testing Compliance & audit support You: Strong cybersecurity/IT services sales track record. Confident selling into mid-market & enterprise. UK based - London commutable 1x per week. Hunter mindset, full sales cycle ownership. Don't just send an email to apply give me a call on 07884666351
-
- CyberArk Architect
- London
- Upto £110,000 plus bonus and benefits
-
Are you ready to lead from the front and drive innovation in the Identity & Access Management (IAM) space? We’re looking for a seasoned CyberArk Architect who has CDE-CPC ideally or experience with privilege Cloud, someone who can lead with vision, execute with precision, and inspire teams to deliver excellence. As a key leader in our organisation, you’ll bring your strong business acumen and a technology-focused, innovative mindset to the table. You’ll be driving strategic initiatives, shaping transformation programs, and empowering teams to think big and deliver even bigger. Acting as a subject matter expert in CyberArk Leading strategic transformations in: Identity Governance Privileged Access Management (PAM) Access Management Customer Identity and Access Management (CIAM) Building and maintaining strong, collaborative relationships within the team Communicating clearly and confidently — both written and verbal — to deliver updates, raise potential issues, and share insights If you are interested in the above position we are looking for people with: deep expertise and a successful track record in IAM strategy, delivery, or assurance with CyberArk Hold relevant certifications such as CDE in Privileged Cloud or Guardian Have experience in a client-facing role (preferred, but not essential) Thrive in a hybrid working environment and are available to work from our or client London office three days a week Lead with clarity, communicate with impact, and adapt quickly to changing priorities
-
- OUTSIDE IR35 Splunk Engineer- SC Cleared.
- United Kingdom
- N/A
-
OUTSIDE IR35 Splunk Engineer- SC Cleared. You will be responsible for consolidating Splunk ES data from multiple feeds into a single pane of glass to enhance visibility and streamline security operations.