On 17 September 2026 at 7:32 a.m. Central European Time, our system was targeted by a coordinated cyberattack originating from multiple locations around the world. The attackers made several million access attempts by systematically testing links to reservation documents. The Cloudflare firewall blocked most of the malicious traffic; however, the attackers also managed to access some valid reservation documents. These links are normally sent to guests by email and are therefore publicly accessible.
During the attack, information from some reservations may have been obtained, including the reservation amount, the guest’s name, and telephone number. This information was subsequently used to send fraudulent messages via WhatsApp. This was a phishing attack intended to establish contact with the recipients of the messages. The exact scope of the reservation information obtained is not yet known; however, based on our findings so far, it appears to have been limited.
Due to the significant increase in traffic, access to the administration interface and website was disrupted between approximately 10:15 and 11:15 a.m. Access was restored after 11:15 a.m., while the attack was fully contained in the afternoon. In the hours that followed, we conducted a detailed review of the situation, analyzed the attack, and identified the vulnerability.
Based on our investigation to date, no other systems were compromised, and there is no indication that the attackers accessed any other personal, financial, or other data belonging to guests or users.
To provide additional protection for reservation documents, we immediately implemented a change requiring guests to enter their telephone number or email address in order to view a document. This provides an additional layer of protection, as the documents cannot be accessed without information known only to the guest.
We advise guests not to open suspicious messages, click on links, or provide any information. If they receive such a message, they should block and report the sender using the “Block and Report” option. Any guest who receives a message should be informed that their reservation remains valid and secure, and that no additional payment is required through the link provided.
We will continue to monitor the system and further strengthen our security measures.
We apologize for any inconvenience this may have caused.