Specialized Victorian travel and cruise agency Needlework Tours suffered a significant threat exposure after an anonymous malicious actor published an allegedly stolen database on an underground hacking forum. Threat intelligence confirmed the presence of a valid sample containing highly sensitive credentials—including full names, passport numbers, issuance timelines, emergency contacts, and profile images—significantly escalating the risk of synthetic identity fraud and sophisticated spear-phishing campaigns targeting international travelers.