alltours.nl
Incident posture
Linked entities
- Victim
- alltours.nl
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A hacker gained unauthorized access to customer booking data through the alltours.nl website, affecting customers who had booked travel online via one of the company's websites. The company's IT department responded immediately, closed the access pathway, and notified all potentially affected customers as a precautionary step. There is no indication that the personal data accessed has been misused in any way. The company reported the incident to the competent supervisory authority under Article 33 of the GDPR, filed a criminal complaint, and is cooperating closely with the cybercrime division of the police and external IT security experts to fully investigate the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A hacker obtained unauthorized access to booking data belonging to alltours customers through the website alltours.nl. According to the company's official press release, the attacker exploited the website to reach booking information of customers who had booked a trip online through one of the company's websites. The alltours IT department responded immediately upon detecting the breach and shut down the access pathway without delay. The company notified all customers who could potentially have been affected by the incident as a precautionary security measure. At the time of the company's public statement, there were no indications that the personal data accessed had been used in any further manner.
The breach was reported to the responsible supervisory authority under Article 33 of the General Data Protection Regulation, specifically the Landesbeauftragte für Datenschutz und Informationsfreiheit NRW (the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia). In addition, alltours filed a criminal complaint. Jan Mayer, Managing Director of Touristik and Finance at alltours, stated that the company had reacted without delay and took the incident extremely seriously, expressing deep regret for the inconvenience caused to customers. Mayer also confirmed that alltours was working closely with the responsible authorities, including the cybercrime division of the police, as well as external IT security experts, in order to fully investigate the incident. The security vulnerability that enabled the unauthorized access was closed following discovery, and the company indicated continued cooperation with investigative and regulatory bodies to clarify the full scope of what occurred.
Sources
Sources available to members: 1 source.