Verizon's 2025 Data Breach Investigations Report analysed 12,195 confirmed breaches across 139 countries. Third-party involvement in breaches doubled from 15% to 30% year on year, and exploitation of vulnerabilities as an initial access step grew by 34%, now accounting for 20% of breaches [1].
Read that third-party figure again in the context of a travel programme. A principal's itinerary passes through an agency, a car company, a hotel, a venue and an assistant's personal device. Every one of them is a third party, and a third of breaches now involve one.
What actually leaks
The five things that should never be an email attachment
Why email is the wrong container
- It copies. Every forward creates an artefact you cannot recall or audit.
- It persists. Attachments outlive the trip by years, in mailboxes and in backups.
- It has no expiry. There is no way to say 'this is valid until Thursday'.
- It has no access list. Anyone with mailbox access has document access.
- It leaves no usable record. You cannot answer 'who saw this passport, and when'.
What a secure channel gives you instead
Email attachment versus secure channel
Practical rules we work to
- Documents go up once, to the channel, and are referenced afterwards - never re-attached.
- Named recipients only. A new person on an account is added deliberately, not by CC.
- Nothing is retained past the movement it belongs to unless you ask us to hold it.
- Anything you ask us to delete is deleted, and we confirm in writing that it is gone.
- Payment details never travel in a message. Ever.
The bottom line
A third of breaches now involve a third party [1], and a travel programme is a chain of third parties by definition. Sending an identity document as an attachment is the single easiest habit to break, and the one with the longest tail if you do not.

