Major Data Breach Hits at Least 100 Dutch Hotels, Putting Thousands of Guests at Risk
At least 100 Dutch hotels have been hit by a data breach, with thousands of guests' reservation details stolen and used in convincing phishing messages.
A major data breach has hit the Dutch hotel sector, with at least 100 hotels affected and the reservation data of thousands of guests stolen and used in scams, hospitality company Hospecs has confirmed. Reports are also coming in from Belgium and Ireland, and the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is investigating.
You’re overpaying your accountant.
Neno gives you a dedicated bookkeeper, automated admin, real-time financial insights and a free business bank account. Everything your business needs, in one place.
No chasing. No surprises. No unnecessary costs.
A widening leak
The alarm was raised by Tim Vissers, managing director of Hospecs, a company that operates hotels and supplies the sector with technology and services. After a breach at his own company, Vissers posted a call on LinkedIn asking other hoteliers whether they were seeing similar signs. The response, he said, was immediate. “We’re being flooded with messages, emails and WhatsApps from affected hotels. Reports are coming in every minute.”
So far, Hospecs estimates that around 100 Dutch hotels have been directly hit, with more incidents being reported from Belgium and Ireland. The exact number is still being mapped out, and chains with dozens of hotels each are also among those affected.
What was stolen, and how it is being used
Criminals have gained access to reservation data including guests’ names, contact details, and arrival and departure dates. They are using this information to send phishing messages that look highly convincing because every detail of the booking is correct. The messages typically impersonate the hotel or booking platform, and ask the guest to make an extra payment or re-confirm their payment details. Some victims have already lost money.
Where the leak appears to sit
Where the data is actually leaking from is still being investigated. According to Vissers, “the first signals suggest there may be a link between the affected hotels and certain systems within the hotel technology and distribution chain, such as PMS, channel management, booking or other connected systems.” In other words, the breach probably sits with a piece of software used by many hotels at once, rather than at any one location.
The Autoriteit Persoonsgegevens has opened an investigation. Under Dutch and EU law, organisations have to report a data breach to the regulator within 72 hours, and it is not yet clear whether all the hotels involved, or Hospecs itself, have done so.
Not a one-off
The pattern is familiar. In January 2026, the booking platform Booking.com became the centre of a similar incident, with criminals using hijacked hotel accounts on the platform to send fake payment requests. In 2025, hundreds of reservations at two hotels in the Van der Valk chain were exposed after an employee clicked on a fake staff login page; guests were then targeted with scam messages and one lost €200. Bastion Hotels also reported a breach that began with a phishing email. Last month, Belgian media reported on hundreds of hotel guests scammed via fake messages claiming a reservation would lapse within 11 hours unless they paid; the details were perfect.
Advice for travellers
The advice from Hospecs and the security community is straightforward. Anyone with a hotel reservation should check the sender of any payment request carefully, ignore links in such messages, and contact the hotel directly through its official phone number or website to verify any unusual request. If money has already been transferred to a fraudster, the bank should be informed at once and a report made to the police.
For the wider sector, the question is how to protect data that, by the very nature of the industry, has to flow through many hands at once. The current investigation is unlikely to be the last word.




