Correction request from HotelNetSolutions GmbH
What HotelNetSolutions GmbH asked
HotelNetSolutions GmbH wrote to us asking for two statements to be corrected within three business days and confirmed by email: "The breach, which lasted for several months" in the summary, and "Data breach period ends – September 13, 2026" in the timeline. The company said the period from January 2026 to 13 September 2026 refers to the dates of reservations associated with reported phishing cases, not the duration of unauthorised access, and that there is no confirmed evidence that unauthorised access continued for several months.
What we changed
Both statements went further than the Heise reporting they summarise, so they were reworded. The summary now says, as Heise does, that the breach may have lasted for months, notes that the company has not confirmed when access began or ended, and states the January to 13 September range as the reported reservation window. The 13 September timeline entry is now labelled as the end of that reported window, not the end of a breach. A March 2026 entry was added for Günter Born's earlier report, which Heise cites.
Nothing else changed. The record that booking data was demonstrably exfiltrated, the 19 September closure, the March 2026 report of a similar phishing wave, and the company's statement to hotels that it cannot reliably attribute exfiltration from its logs all remain, because they are the published facts on which the open question of duration rests.
Our response
We have reviewed our article against the Heise reporting it summarises.
Two statements have been reworded. The summary now says, as Heise does, that the breach may have lasted for months, and the timeline entry for 13 September 2026 now describes that date as the end of the reservation window you reported, not as the end of unauthorised access. Those changes are made because our wording went further than the source, not because a duration has been ruled out.
On that point, the record as published by Heise stands and remains reflected in our article: your company confirmed that booking data was demonstrably exfiltrated through a vulnerability closed on 19 September; it told affiliated hotels that it cannot reliably attribute abusive exfiltrations retrospectively from its logs; it declined to tell Heise when access began or how many hotels are affected; and Günter Born reported a phishing wave using data presumably taken from your platform around March 2026. The absence of confirmed evidence about the access period is a consequence of those facts, and our summary says so.
ThreatCluster aggregates and summarises public reporting. We do not accept correction deadlines from the subjects of that reporting, and we do not provide confirmations by email. If you publish a confirmed access period, or if Heise amends its reporting, our summary will reflect it. If you believe Heise's reporting is inaccurate, that is a matter to raise with Heise.
ThreatCluster summarises published reporting and leak-site listings. All corrections are listed at /corrections.