

![]()
Vacansoleil has undergone a similar misadventure.
The company, which is part of the Maeva group, admits to having been compromised.
In a message published at the end of May, the platform explains that it “identified on May 14, 2026 a security incident that resulted in unauthorized access to certain personal data used in the preparation of stays“.
Vacansoleil’s teams, supported by experts, reacted immediately and were able to identify and fix the flaw.
The FNHPA Was Also Hacked
This could pave the way for phishing campaigns targeting people who have made a booking on the platform.
Moreover, individuals who obtain the hacked database could attempt to contact customers by phone or SMS to request payments for upcoming stays.
Beyond the negative publicity and the erosion of trust with internet users, a breach can be costly for a company. The latest example is none other than the €1.8 million fine imposed by the CNIL on Voyageurs du Monde.
The FNHPA is also believed to have been compromised, notably the Occitanie Federation of Outdoor Hospitality. Thus, the attackers reportedly published 6,419 establishment or organization records, as well as 2,605 invoices covering the period from March 19, 2024 to May 12, 2026. The breach would not involve customer profiles but would exclusively concern camping professionals.
Tourism Must Tackle Cybersecurity Head-On
“”In the weeks to come, every player in the sector will claim that they take security seriously. The word has lost all value. Everyone says it, including those who have learned it the hard way.
What will now count is the ability to demonstrate it in a structured, verifiable, and recurring manner. That is precisely the function of an information security management system.
The question is no longer merely ‘am I protected?’, it becomes ‘am I able to prove, to a client, to a partner, to the CNIL, that my protection rests on a system and not on luck’,” explained Christophe Mazzola, a cybersecurity expert, in his latest column on TourMaG.com.
