---
title: Wakacje.pl confirms customer data breach following cyberattack
url: https://www.dataloco.com/en/wakacjepl-confirms-customer-data-breach-following-cyberattack
published: 2026-10-07T17:20:31+00:00
language: en
section: Security
source: https://crn.pl/aktualnosci/cyberatak-i-wyciek-danych-z-wakacje-pl-wakacje-pl/
organizations: Wakacje.pl, Check Point, Booking.com, CERT Polska, Itaka
publisher: Dataloco
---

# Wakacje.pl confirms customer data breach following cyberattack

The online travel service Wakacje.pl confirmed that a cyberattack resulted in a breach of personal data. The incident occurred on September 29, 2026, when attackers gained access to the customer service system and several email accounts. The company stated that the systems handling payments were not compromised. Additionally, the leaked data does not allow attackers to log into the customer panel or the application. The service has notified affected customers and provided recommendations, including blocking their national identification numbers. An investigation into the breach is currently underway.

The data that may have been leaked includes first and last names, dates of birth, passport details, email addresses, residential addresses, and phone numbers. This incident follows a series of data breaches in the medical sector. According to Check Point, the average number of cyberattacks on Polish companies and institutions increased by 10 percent year over year in September 2026, reaching approximately 2,000 attacks per week per entity. Globally, organizations in the hotel, tourism, and recreation sectors experienced an average of 2,913 cyberattacks per week per organization in September 2026. This figure is nearly 50 percent higher than the previous year and represents a growth of more than 180 percent over three years.

Recent incidents in the travel industry include a breach disclosed in April 2026 involving Booking.com, where unauthorized individuals accessed some user data. CERT Polska confirmed that users from Poland were among those affected. In autumn 2025, the company Itaka was the target of an incident, though it stated that attackers did not access reservation data, financial data, trip participant information, or national identification numbers. Wojciech Głażewski, director of Check Point Software Technologies in Poland, noted that attacks on travel services are particularly dangerous because these companies process a wide range of personal data, making them attractive targets for information theft groups and ransomware or phishing operators.

## This story in other languages

- [Nederlands](https://www.dataloco.com/nl/cyberaanval-en-gegevenslek-bij-wakacjepl)
