ctipilot.ch
← Back to Daily brief 2026-06-04
HIGHincident

Shared booking-software breach exposes guests at 100+ Dutch, Belgian and Irish hotels; phishing wave already underway

discovered 2026-06-04 05:00 UTCrun 2026-06-04-51b23ffa2 sourcesmulti-source

More than 100 hotels in the Netherlands plus properties in Belgium and Ireland had guest reservation records (names, contact details, arrival/departure dates) exposed through a shared booking / channel-management / property-management SaaS layer rather than any single hotel's own systems (DutchNews.nl, 2026-06-03 · Techzine EU, 2026-06-03). Hospecs, coordinating the response, attributes the root cause to the upstream provider; the Dutch DPA (Autoriteit Persoonsgegevens) has opened an investigation and GDPR Art. 33/34 clocks are running for each hotel as an independent controller. Criminals are already sending contextually accurate "confirm and pay for your reservation" phishing referencing real upcoming stays.

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.