

![]()
After Belambra, Maeva, and Gîtes de France… here is a new name in tourism to feature on the pirates’ bucket list.
Vacansoleil has undergone a similar misadventure.
The company, which is part of the Maeva group, admits to having been compromised.
In a message published at the end of May, the platform explains that it “identified on May 14, 2026 a security incident that resulted in unauthorized access to certain personal data used in the preparation of stays“.
Vacansoleil’s teams, supported by experts, reacted immediately and were able to identify and fix the flaw.
Vacansoleil has undergone a similar misadventure.
The company, which is part of the Maeva group, admits to having been compromised.
In a message published at the end of May, the platform explains that it “identified on May 14, 2026 a security incident that resulted in unauthorized access to certain personal data used in the preparation of stays“.
Vacansoleil’s teams, supported by experts, reacted immediately and were able to identify and fix the flaw.
The FNHPA Was Also Hacked
The volume of data exfiltrated has not been disclosed, but names, first names, telephone numbers and reservation details, as well as the dates and locations of stays, were extracted by the attackers.
This could pave the way for phishing campaigns targeting people who have made a booking on the platform.
Moreover, individuals who obtain the hacked database could attempt to contact customers by phone or SMS to request payments for upcoming stays.
Beyond the negative publicity and the erosion of trust with internet users, a breach can be costly for a company. The latest example is none other than the €1.8 million fine imposed by the CNIL on Voyageurs du Monde.
The FNHPA is also believed to have been compromised, notably the Occitanie Federation of Outdoor Hospitality. Thus, the attackers reportedly published 6,419 establishment or organization records, as well as 2,605 invoices covering the period from March 19, 2024 to May 12, 2026. The breach would not involve customer profiles but would exclusively concern camping professionals.
This could pave the way for phishing campaigns targeting people who have made a booking on the platform.
Moreover, individuals who obtain the hacked database could attempt to contact customers by phone or SMS to request payments for upcoming stays.
Beyond the negative publicity and the erosion of trust with internet users, a breach can be costly for a company. The latest example is none other than the €1.8 million fine imposed by the CNIL on Voyageurs du Monde.
The FNHPA is also believed to have been compromised, notably the Occitanie Federation of Outdoor Hospitality. Thus, the attackers reportedly published 6,419 establishment or organization records, as well as 2,605 invoices covering the period from March 19, 2024 to May 12, 2026. The breach would not involve customer profiles but would exclusively concern camping professionals.
Tourism Must Tackle Cybersecurity Head-On
The list of information posted on the dark web is long. It includes, among other things, the names of establishments, their corporate names, their SIRET numbers, the number of locations, their latitude and longitude, their FNHPA member numbers, invoices, and the issuer’s IBAN, RIB, and BIC…
“”In the weeks to come, every player in the sector will claim that they take security seriously. The word has lost all value. Everyone says it, including those who have learned it the hard way.
“”In the weeks to come, every player in the sector will claim that they take security seriously. The word has lost all value. Everyone says it, including those who have learned it the hard way.
What will now count is the ability to demonstrate it in a structured, verifiable, and recurring manner. That is precisely the function of an information security management system.
The question is no longer merely ‘am I protected?’, it becomes ‘am I able to prove, to a client, to a partner, to the CNIL, that my protection rests on a system and not on luck’,” explained Christophe Mazzola, a cybersecurity expert, in his latest column on TourMaG.com.
