CSIDB logo
Incident

alltours.nl

Incident posture

Attack window
Nov 2025
Location
Netherlands
Status
Resolved
CIA posture
Available to members
Updated
2026-08-17 17:50

Linked entities

Victim
alltours.nl
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2025
Resolved
Undetermined

Summary

The website alltours.nl was compromised when a hacker gained unauthorized access to booking data of customers who had made reservations through the site. The operator’s IT team promptly closed the entry point, notified all potentially affected customers, and stated that there is no indication the data were misused. The incident was reported to the relevant data‑protection authority under GDPR and a police complaint was filed, while the company continues to cooperate with law‑enforcement and external security experts to fully investigate the breach.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

A hacker gained unauthorized access to the alltours.nl website and obtained booking data of customers who had made online trip reservations through the company's web presence. The alltours IT department detected the breach and immediately closed the pathway used by the attacker. Following the containment, the company notified all customers who might have been affected by the incident for security reasons. The company stated that there were no indications that the accessed personal data had been further used or disseminated in any form. The incident occurred in early February 2025, as indicated by the press release date of February 1, 2025. The breach was confined to the booking data accessible via the alltours.nl web interface. No other systems or data stores were mentioned as compromised in the source material. The company’s immediate response included technical containment and customer communication. The notification to customers was carried out as a precautionary measure despite the lack of evidence of misuse. The press release emphasized that the access route was shut down without delay.

In accordance with Article 33 of the General Data Protection Regulation, alltours reported the incident to the competent supervisory authority, the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen. The company also filed a criminal complaint with law enforcement agencies. alltours announced that it is working closely with the police cybercrime division and external IT security experts to fully investigate the breach. Jan Mayer, the alltours Geschäftsführer für Touristik und Finanzen, stated that the company reacted immediately and takes the incident very seriously. He expressed regret for the inconvenience caused to customers. The statement underscored the company’s commitment to transparency and cooperation with authorities. No further details about the attacker’s identity or motives were disclosed in the source. The company’s internal investigation is being supported by external forensic specialists. The press release did not mention any regulatory fines or penalties resulting from the notification. The overall response combined technical remediation, legal reporting, and stakeholder communication.

alltours describes itself as a travel operator with a fifty‑year history, serving approximately 2.3 million guests in the financial year 2023/24 and ranking among the three largest travel organizers in Germany and within the top ten in Europe. The company reports a brand awareness level of ninety-two percent. The alltours group comprises the alltours and byebye tour operators, alltours Reisecenter travel agencies, the incoming agency Viajes allsun, and the allsun hotel chain. This background provides context for the scale of the potential impact on customers and the organization’s operational footprint. The press release did not specify any financial losses, service disruptions, or long‑term reputational effects beyond the customer notifications and the described remedial actions.

Sources

Sources available to members: 1 source.

CSIDB