A phishing wave via email and WhatsApp is currently underway targeting customers of hotels in Germany and neighboring countries. At least part of the incidents appear to stem from a data breach at booking service provider HotelNetSolutions GmbH, which may have lasted for months. According to its own statements, this provider manages bookings for “over 2500 hotels and hotel groups” through its “OnePageBooking” platform.
The Berlin-based company announces on an information page that it was able to “confirm and close the vulnerability in an interface between HotelControl and a connected hotel system (PMS)” on September 19. In a statement to the connected hotels, which is available to heise online, it states: “Based on the technical findings currently available to us, booking information was demonstrably exfiltrated via the vulnerability.” This included, among other things, the name of the booked hotel, the guest’s name, the guest’s email address and phone number, the booking number, arrival and departure dates, and the total booking amount.
With this information, criminals have apparently been able to create very credible phishing messages. Hotel guests have been and continue to be asked to repay failed payments for hotel stays or to provide their credit card details. According to information from heise online, financial damage has already occurred to hotel guests who fell for this scam. HotelNetSolutions advises hotel guests to be extra vigilant and to critically examine payment requests.
It remains unclear so far when the attackers accessed the data and how many bookings are affected. The company merely writes: “According to the current status, reservations from the period January 2026 up to and including September 13, 2026, are being reported to us.” In his blog Borncity, Günter Born reported at least half a year ago a phishing attack with customer data presumably stolen from HotelNetSolutions. The provider itself stated to the hotels that it could not “reliably” attribute abusive exfiltrations from existing log files retrospectively.
Upon inquiry from heise online, HotelNetSolutions declined to provide further details and did not answer questions the period of data access or the number of affected hotels, instead referring to the information already published. From a data protection perspective, the provider acts as a processor for the affiliated hotels, according to its own statements, and thus not as a controller within the meaning of the GDPR.
Therefore, from a data protection standpoint, the hotels are more responsible for informing the affected guests. If the data breach is likely to result in a high risk to the rights and freedoms of the guests, they must inform the data subjects pursuant to Art. 34 GDPR without undue delay. heise online already has corresponding notification emails from individual hotels to their guests.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
