This page is the central source of information regarding the data protection incident. New relevant findings will be published exclusively here.
Key Information for End Customers Regarding the Data Protection Incident
Update on the Data Protection Incident – Completion of the External Security Analysis
An independent cybersecurity firm was commissioned to investigate the incident. The analysis has now been completed.
The investigation confirmed that an unauthorized third party gained access to customer data, which was subsequently misused
for targeted phishing attempts.
Important to know:
- There is no evidence that data was altered or deleted.
- The systems continue to operate securely.
- The unauthorized access has been stopped.
- Additional security measures have been implemented.
What does this mean for you?
The attacker may have attempted to contact you via messages (e.g., WhatsApp or email) while impersonating a hotel or booking platform.
These messages may contain links to fraudulent websites designed to steal payment information.
You
will never be asked to provide payment details via WhatsApp or SMS.
What you should do
Please note the following:
- Do not click on suspicious links.
- Do not enter payment details on unknown websites.
- If in doubt, contact your hotel directly.
- If you have already entered your details, please contact your bank immediately.
Our Measures
The incident has been thoroughly investigated and additional security measures have been implemented to further protect the systems.
Swoppen continues to work with external security experts to continuously improve security standards.
Update – Status: 02.02.2026 12:05 Uhr
What happened?
As part of a current investigation, it was determined that unauthorized access to personal data occurred in connection with bookings or reservations that were processed via a booking/management software in use.
The responsible authorities have been informed, and the incident is currently being thoroughly investigated together with independent external IT security companies.
Information & Updates
How will new information be communicated?
All new findings relevant to the data protection incident will be continuously published centrally on this page. Individual notifications to specific persons regarding interim statuses or detailed information will not be provided.
Which data may be affected?
According to current knowledge, the following data may be affected, among others:
- First and last name
- Email address
- Telephone number
- Postal address
- Booking or stay details (e.g. arrival and departure dates)
Depending on how the system was used by the respective customer, payment data may also be affected if corresponding functions were used.
Credit card information – if stored – is processed exclusively in encrypted form. According to current knowledge, there are no indications of decryption or misuse of this data.
Why am I receiving suspicious messages?
As a result of the incident, targeted phishing attacks are currently taking place, including via email or WhatsApp. Some of these messages appear very authentic and refer to actual bookings or stays.
The aim of these messages is to induce recipients to enter payment or access credentials.
Important Security Notices
Please note:
- Do not click on any links in unexpected or suspicious messages.
- Do not enter any payment or credit card details.
- Do not share any access credentials.
Reputable providers do not request booking confirmations or payments via WhatsApp or external websites.
What should you do now?
We recommend that you:
- Do not respond to suspicious messages
- Delete or document the messages (e.g. screenshot)
- Change passwords as a precaution, especially if they are also used elsewhere
- If in doubt, contact the company you booked with directly
Which measures have been taken?
- Notification of the incident to the competent data protection supervisory authority
- Filing of a criminal complaint
- Engagement of independent external IT security companies
- Implementation of additional technical and organizational security measures
Who can I contact?
This central information page is available for general information about this incident.
For booking-specific questions, please contact the company with which you made your booking directly.
🔐 Data Protection Notice
The protection of personal data is a top priority. We sincerely regret the inconvenience caused and provide transparent information about new findings.

