1. Home
  2. News
  3. Cyber attack on holiday provider
  • Data Protection

Cyber attack on holiday provider

Anyone who has booked their next holiday with Center Parcs by phone should be particularly vigilant at the moment: The company has been the target of a hacker attack. The attackers managed to access sensitive customer data - at least temporarily.

According to an email currently being sent to affected customers, the attack took place at the beginning of June. Cyber criminals were able to access information such as names, email addresses, travel dates and booking numbers via an interface that is used specifically for telephone bookings. According to Center Parcs, financial data, passwords or addresses were not affected - and there is no evidence of data manipulation to date.

As soon as the incident was recognised, the company said it reacted by stopping system access and tightening security measures. The incident has now also been reported to the relevant authorities and external IT security professionals are helping to secure the systems.

Although the attack was quickly contained, Center Parcs advises caution: phishing attempts by email, text message or phone call could follow. Particularly dangerous: fraudulent payment requests that claim to be related to existing bookings. Centre Parcs expressly emphasises that payment information is only communicated via the official website or the MyCP app.

Such incidents once again illustrate how quickly personal information can fall into the wrong hands - even at established companies. Anyone who now receives sceptical messages should look twice and, if in doubt, ask directly via the official channels.

Source: https://www.heise.de

 

About Cookies

This website uses cookies. Those have two functions: On the one hand they are providing basic functionality for this website. On the other hand they allow us to improve our content for you by saving and analyzing anonymized user data. You can redraw your consent to to using these cookies at any time. Find more information regarding cookies on our Data Protection Declaration and regarding us on the Imprint.
Mandatory

These cookies are needed for a smooth operation of our website.

Name Purpose Lifetime Type Provider
CookieConsent Saves your consent to using cookies. 1 year HTML Website
fe_typo_user Assigns your browser to a session on the server. session HTTP Website
PHPSESSID Temporary cookies which is required by PHP to temporarily store data. session HTTP Website
__cfduid missing translation: trackingobject.__cfduid.desc 30 missing translation: duration.days-session HTTP Cloudflare/ report-uri.com
Statistics

With the help of these statistics cookies we check how visitors interact with our website. The information is collected anonymously.

Name Purpose Lifetime Type Provider
_pk_id Used to store a few details about the user such as the unique visitor ID. 13 months HTML Matomo
_pk_ref Used to store the attribution information, the referrer initially used to visit the website. 6 months HTML Matomo
_pk_ses Short lived cookie used to temporarily store data for the visit. 30 minutes HTML Matomo
_pk_cvar Short lived cookie used to temporarily store data for the visit. 30 minutes HTML Matomo
MATOMO_SESSID Temporary cookies which is set when the Matomo Out-out is used. session HTTP Matomo
_pk_testcookie missing translation: trackingobject._pk_testcookie.desc session HTML Matomo