Dutch hotels data breach: stolen bookings became fake payment requests within days
TL;DR
On 2 June 2026, a data breach surfaced in the reservation software many hotels use, confirmed by hotel management company Hospecs. At least 100 Dutch hotels are affected, with reports from Belgium and Ireland; the stolen data covers names, contact details, and arrival and departure dates for thousands of guests. Within days, guests with active bookings received fake payment requests quoting their real reservation, and some lost thousands of euros. The Autoriteit Persoonsgegevens has opened an investigation and KHN warned travellers to verify senders.
Incident Response PlaybookExpand
- Confirm with your reservation software supplier whether your property's data was in scope, and over what window.
- Preserve evidence: booking system logs, export history, API activity, and guest fraud reports, before retention windows close.
- Identify which reservation records were exposed and which fields: name, contact details, arrival and departure dates.
- Warn guests with active or upcoming bookings directly, through a channel they already trust, that fraudulent payment requests are circulating.
- Publish a clear statement on your own website and at reception: how you will and will not ask for payment.
- Brief front-desk and reception staff to expect guest questions and to recognise the fraud pattern.
- Rotate credentials and API tokens shared with the booking platform, and enforce MFA on staff accounts.
- As controller, notify the Autoriteit Persoonsgegevens within 72 hours. Do not wait for the supplier to notify on your behalf.
- Notify affected guests under AVG with specific guidance on what the exposed data enables.
- Report the fraud to the politie (Team Cybercrime) and collect victim reports for the investigation.
- Re-examine your supplier contract: how fast must they tell you, and what are their security obligations.
- Run a post-incident review of which third parties touch your guest data and how you would detect a supplier breach faster.
The breach became fraud before the guests checked out
The Dutch hotels data breach that surfaced on 2 June 2026 stands out for one reason: how fast it turned into money. Most stolen datasets sit quietly for months before anyone abuses them. This one did not. Within days of the leak, guests with real, current bookings were getting payment requests that quoted their actual reservation, the correct hotel, the correct dates, their own name. At least 100 Dutch hotels are affected, with further reports from Belgium and Ireland. The data came out of the reservation software that hotels use to take and manage bookings, which is why so many properties were hit at the same time.
That timing is the whole story. A stolen booking is worth little on its own. Turned into a payment request that a guest half-expects to receive, it becomes a working fraud, and the criminals moved on it fast.
What happened
The incident was confirmed by Hospecs, a Dutch company that operates hotels and provides services to the sector, through managing director Tim Vissers. NOS first reported it on 2 June 2026, and by the following day Vissers said reports of affected hotels kept coming in.
The stolen information is booking data: guest names, contact details, and arrival and departure dates, with payment details exposed in some cases. Thousands of guests are involved across the affected hotels. Koninklijke Horeca Nederland (KHN) urged the sector to stay alert and told travellers to check who a message really comes from before acting on it. The Autoriteit Persoonsgegevens, the Dutch data protection authority, has opened an investigation.
The damage is already concrete. According to itdaily, one hotel manager said some guests "have already lost thousands of euros." The fraudulent messages arrive by email and WhatsApp, and Vissers estimated dozens of them a day, with the potential to reach hundreds or thousands as the criminals work through the stolen data.
How the attack worked
The leak does not sit inside any single hotel's own network. It sits in the reservation software chain that many hotels share, which is what turned one compromise into a sector-wide problem. A booking passes through several systems between the moment a guest reserves a room and the moment that reservation lands in the hotel's own records, including a layer that calculates pricing. According to NOS, Vissers put it plainly: the leak is probably in the software that hotels use, somewhere in one of those intermediary layers.
Beyond that, be honest about what is not known. The specific software product has not been named publicly, the exact entry point is still under investigation, and no group has claimed responsibility. Guessing at attribution or technique helps no one. What the incident already shows clearly is the shape of the risk: when many hotels depend on the same booking platform, a weakness in that shared layer exposes all of them at once, without an attacker ever touching an individual hotel's systems. That is the same supplier-concentration problem that keeps producing sector-wide breaches, arriving here through the booking chain rather than the front door.
Who is affected
The people directly exposed are guests with bookings at the affected hotels: at least 100 in the Netherlands, plus hotels in Belgium and Ireland. The stolen fields look modest on paper, a name, contact details, and the dates of a stay, but that combination is exactly what makes the follow-on fraud work. A message that already knows your hotel, your dates, and your name does not read like a scam. It reads like the hotel.
That is why the fake payment requests have been effective. The criminals are not guessing. They quote a real reservation back to the guest and ask for a payment or a payment confirmation, often with urgency and often over WhatsApp, where people are less guarded than in email. For an organisation, the exposure runs through staff and corporate travel: anyone whose room was booked through an affected hotel could receive one of these messages, and a finance-adjacent employee acting on a convincing request is how money leaves the building.
For the affected hotels themselves, the reporting duty does not wait for the software supplier. Each hotel is the controller of its own guests' data under the AVG, which means each carries its own obligation to assess the breach and, where it meets the threshold, notify the Autoriteit Persoonsgegevens within 72 hours. The supplier's statement does not discharge that duty.
What this means for your organisation
Three lessons carry beyond the hotel sector.
First, a breach at shared software is a breach at every organisation that uses it. No hotel here was hacked in the ordinary sense, yet each affected property now carries the notification duty, the guest communication, and the reputational cost. If you rely on a booking platform, a scheduling tool, or any supplier that holds your customers' data, their incident becomes your incident the moment it happens. Map which suppliers touch your customer data and confirm in writing how fast they will tell you when something goes wrong.
Second, the gap between breach and abuse has collapsed. The old assumption that stolen data surfaces slowly, months later, in some distant fraud attempt does not hold here. Guests were being defrauded while their bookings were still active. If your incident plan assumes you have weeks before stolen data is used, this case is a correction.
Third, the quality of the data is what makes the phishing land. Training that teaches people to spot typos and strange senders will not catch a message that quotes a real reservation. The defence is a mix of warning affected people directly, giving them a clear rule for how you will and will not ask for payment, and briefing the staff most likely to be targeted.
If your organisation is dealing with an active data breach right now, or your guests and customers are being defrauded with data taken from your systems, SecDesk's incident response team works directly with Dutch organisations from containment through regulator notification. You can reach the team at response.secdesk.com.
Talk to a senior responder about Dutch hotels data breach: stolen bookings became fake payment requests within days.
Schedule a response callNeed incident response?
- Two-hour SLA
- Dutch senior responders
