Cyber Incident Victim: Finland
Date:
Feb 2022
Location:
Finland
Summary
A cyberattack targeting Nordic Hotels and Resorts compromised nearly 16,000 customer records from its F6 and Kämp properties in Helsinki, with potential spillover to other Finnish hotels. Exposed data included names, contact details, addresses, and stay dates primarily from historical bookings. The breach occurred over several days in early February but was detected approximately two months later, prompting notifications to affected customers via email. The hotel group confirmed resolving the vulnerability, assuring secure online reservations, and reported the incident to Finnish data protection authorities and law enforcement. While the attack vector originated through a third-party service provider, the full scope of impacted hotels remains undisclosed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
A data breach impacting multiple hotels in Finland occurred between February 10 and February 14, 2022, targeting systems operated by a service provider for Nordic Hotels and Resorts (Nordic Choice Hotels). The breach specifically affected Helsinki-based properties Hotel Kämp and F6 Hotel, compromising personal data of 15,947 customers accumulated from 2019 onward, though not all guests during that period were impacted. Exfiltrated information included full names, phone numbers, physical addresses, email addresses, and dates of hotel stays. Nordic Choice Hotels became aware of the incident on April 9, 2022, and formally reported it to Finland’s Data Protection Ombudsman and the Finnish Police on April 12. The company confirmed the attack also affected several other Finnish hotels beyond their portfolio, though specific identities remained undisclosed due to contractual arrangements between the compromised service provider and impacted establishments.

Nordic Choice Hotels notified affected customers via email, disclosing the nature of the exposed data and confirming the breach originated from their third-party provider’s systems. The company stated the vulnerability enabling the attack had been remediated by April 2022, declaring online reservation systems secure for future bookings. No financial data or payment card information was confirmed as compromised in the breach. Internal investigations and coordination with the external provider continued following the mandatory regulatory notifications. The hotel group emphasized prioritizing guest safety but did not disclose specific forensic findings regarding the attack vector or perpetrator identity. Impact assessments indicated the breach scope might expand as additional hotels linked to the same service provider could be affected, though no further details were verified at the time of disclosure.
