CSIDB logo
Incident

alltours.nl

Incident posture

Attack window
Feb 2025
Location
Netherlands
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 17:35

Linked entities

Victim
alltours.nl
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacker gained unauthorized access to customer booking data through the alltours.nl website, affecting customers who had booked travel online via one of the company's websites. The company's IT department responded immediately, closed the access pathway, and notified all potentially affected customers as a precautionary step. There is no indication that the personal data accessed has been misused in any way. The company reported the incident to the competent supervisory authority under Article 33 of the GDPR, filed a criminal complaint, and is cooperating closely with the cybercrime division of the police and external IT security experts to fully investigate the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A hacker obtained unauthorized access to booking data belonging to alltours customers through the website alltours.nl. According to the company's official press release, the attacker exploited the website to reach booking information of customers who had booked a trip online through one of the company's websites. The alltours IT department responded immediately upon detecting the breach and shut down the access pathway without delay. The company notified all customers who could potentially have been affected by the incident as a precautionary security measure. At the time of the company's public statement, there were no indications that the personal data accessed had been used in any further manner.

The breach was reported to the responsible supervisory authority under Article 33 of the General Data Protection Regulation, specifically the Landesbeauftragte für Datenschutz und Informationsfreiheit NRW (the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia). In addition, alltours filed a criminal complaint. Jan Mayer, Managing Director of Touristik and Finance at alltours, stated that the company had reacted without delay and took the incident extremely seriously, expressing deep regret for the inconvenience caused to customers. Mayer also confirmed that alltours was working closely with the responsible authorities, including the cybercrime division of the police, as well as external IT security experts, in order to fully investigate the incident. The security vulnerability that enabled the unauthorized access was closed following discovery, and the company indicated continued cooperation with investigative and regulatory bodies to clarify the full scope of what occurred.

Sources

Sources available to members: 1 source.

CSIDB