

![]()
While the sector rode its peak activity, the country lived another high season. About fifty data breaches confirmed by their own victims in August alone, according to the tally kept by FrenchBreaches as of August 23.
The Directorate-General for Public Finances, with more than 670,000 taxpayers exposed via an internal tool linked to impots.gouv.fr, then more than two million property owners via cadastral data.
The Ministry of National Education, 43 gigabytes. SFR and its 2.1 million accounts. Intermarché drive, 1.7 million. The Civil Protection, 525 000 profiles, including minor volunteers. Inserm, Santé publique France, Bloctel, the Hospices Civils de Lyon, the national dog and cat identification file, the French Handball Federation.
You may notice there is no tour operator, no hotel chain, no travel agency, nor incoming operator. That is precisely why you should read this list.
Because what Summer 2026 has brought back on the table is not a sector issue. It is a matter of trust, and trust is the raw material of your trade, far ahead of mine.
I am going to do something unusual in these pages: speak very little about tourism, and a lot about the resilience of a company when it takes a hit.
Size has never been a guarantee, and summer just proved it
A telecom operator, meaning a company whose core business is the network. A major retailer. Three months earlier, in May, it had been Pierre & Vacances-Center Parcs, Belambra and Gîtes de France within 72 hours, i.e., the most established players in the French hospitality sector.
Read on this: Three breaches in three days: why tourism will have to prove its security
It follows, then, that the uncomfortable conclusion is warranted: the size of a player does not say anything about its security. It only reveals the extent of what it exposes.
When you pick a booking engine, a channel manager, a CRM, or a payment provider, assuming that a large supplier is automatically a reliable one is a mental shortcut, not an analysis.
Our brain equates notoriety with reliability because it is energy-efficient, and because it relieves us of making an uncomfortable decision. Attackers know this reflex better than we do and live on it.
You are not always the target. You are sometimes the path
The attacker claims access to around 159 client environments out of the 230 the platform supports; the publisher acknowledged the intrusion on August 8 and only confirms thirteen. Whatever the number, thirteen companies have since reported a breach related to this incident, for a total of 185 gigabytes. None of them were hacked. They were affected.
The CNIL’s annual report, published in May, quantifies this mechanism with brutal clarity. The authority received 17,802 data-violation notifications in 2025. It removed 11,635 from its trend statistics because they all stemmed from the compromise of two software publishers and cascaded down from their clients.
Two providers alone accounted for two-thirds of that year’s notifications.
In tourism, the Gîtes de France breach went through the servers of its IT service provider, not through its own.
And you must read this mechanism in both directions. If a compromised provider exposes its clients, a small organization that is compromised exposes those it serves.
Your access key to a major tour operator’s system, your partner access to a reservation hub, your email account authenticated with a client that treats your messages as legitimate: all of this is worth far more to an attacker than your own customer base.
Your small size is not protection. In a highly interconnected ecosystem like yours, it is a commercial argument for the attacker aiming higher.
What protects has never been front-page news
Polite paranoia
It means asking your providers the questions you wish your own clients would ask you:
– where are my data hosted?
– how many of your employees can read them?
– within what timeframe will you notify me in case of an incident, and by what channel?
– when was your last penetration test, and what were the results?
– what happens to my data the day I leave?
These questions require no technical expertise. They merely require accepting a moment of awkwardness in a business relationship, which is often the real obstacle.
Restoring trust is not announced, it is demonstrated
The first is what you do not hold. A reservation history going back to 1995, as seen with Gîtes de France, is not an asset; it becomes a liability. Each year kept unused is another year offered to whoever might come in. A deletion policy is a security measure, not a legal formality.
The second is your ability to speak quickly and accurately. The 72 hours of the GDPR are not a communication objective; they are the window in which your client decides whether to keep trusting you. The CNIL, which issued 487 million euros in fines in 2025 and sanctioned for the first time a subcontractor on par with a data controller, has announced it will tighten its checks in 2026 on large databases. Silence now costs both sides.
The third is the most profitable, and no one is exploiting it. Make security a business argument. Tourism knows how to market an environmental standard, a quality label, a service certification. It does not yet know how to tell a client, or a principal, what it does with their data and why it does it better than a competitor. Yet this is the only realm where trust can be rebuilt faster than it is lost.
The regulatory calendar, however, will not help you. The NIS2 directive should have been transposed in France by October 17, 2024; the Resilience bill was adopted by the Senate in March 2025 and is still awaiting passage in the Assembly, now hoped for September.
On July 8, the European Commission referred France to the Court of Justice of the European Union, seeking daily fines. And once the text is approved, entities will have three years to comply.
Do not wait for that timetable, because it is not the one that will compel you. Your real deadline is the next security questionnaire your biggest client will send you. Article 21 of NIS2 requires every regulated entity to secure its supply chain, meaning it will audit you, whether you fall within the text or not.
The market will regulate before the legislator, and it already is doing so.
The day an op operator tender includes a serious security annex rather than a checkbox, the sector will have stopped outsourcing trust to parties it does not evaluate.
Until then, trust will continue to be misplaced at that exact spot where no one watches: at the neighboring service provider.
Who is Christophe Mazzola?

His objective: make cybersecurity accessible to everyone.
A speaker, author, and CISO, he supports companies and institutions with a pragmatic approach to digital security, at the crossroads of leadership, pedagogy, and digital sovereignty.

