
Hackers breach Polish travel portal Wakacje.pl, leaking customer passport and personal data
Polish travel agency Wakacje.pl reported a security breach affecting customer service systems and staff mailboxes on 29 September 2026, compromising passport details, birth dates, and contact information.
Scope of the breach
Polish travel booking platform Wakacje.pl experienced a cyberattack on 29 September 2026, resulting in unauthorized access to customer records. Attackers compromised several internal corporate email inboxes belonging to company staff as well as the platform's customer management system. The exposed information encompasses full names, residential addresses, telephone numbers, email addresses, dates of birth, and passport details. While company officials confirmed the infiltration, the exact number of affected users remains unquantified in public statements.
Wakacje.pl clarified that the compromised data does not grant attackers entry to the customer panel on either the website or the mobile application. The company also confirmed that its payment processing architecture was entirely unaffected by the breach. To mitigate immediate risks, the agency introduced supplementary defensive procedures and began monitoring internal traffic to identify any anomalous transactions or unauthorized operations.
We apologize for this situation. We ensure that our teams are working to minimize the consequences of this event.
Phishing risks and consumer advisories
The platform issued warnings alerting clients to the risk of financial extortion following the incident. Cybercriminals could leverage the obtained passport numbers, addresses, and travel booking details to impersonate travel agents, hotels, or holiday tour operators. These fraudulent actors could attempt to solicit fraudulent booking fees or demand scanned identity papers from travelers.
It is worth remaining vigilant toward messages requesting payments or booking changes and verifying them with your advisor, as attackers may use the accessed data for extortion attempts by posing as Wakacje.pl.
Cybersecurity portal Niebezpiecznik advised affected individuals to evaluate the exact data stored by the travel portal and promptly annul or restrict documents that can be secured. Experts and the company recommended that customers register official restrictions on their national identification numbers (PESEL) and passport records. Customers were urged to contact their designated travel advisors directly to authenticate any suspicious requests regarding payment alterations or reservation modifications.
- Unauthorized actors penetrate Wakacje.pl customer service systems and staff email accounts.
- Wakacje.pl publicly discloses the breach, alerts CSIRT NASK and UODO, and issues customer fraud advisories.
Threat actor context and state response
The incident occurred alongside several high-profile cyberattacks on private Polish entities. Cybersecurity researchers at Niebezpiecznik verified that the hacker known as Fingerprint, who was behind recent intrusions at healthcare and billing platforms MyDr, Enel-Med, and Fakturownia.pl, was not responsible for the Wakacje.pl incident. In direct communications with the outlet, Fingerprint stated that they did not conduct the attack and do not intend to target Polish companies going forward.
Wakacje.pl officially submitted notifications regarding the intrusion to the Personal Data Protection Office (UODO) and the CSIRT NASK national cybersecurity agency, while preparing reports for law enforcement authorities. Poland's Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski emphasized that private sector firms need to expand their cyber defense spending and security measures. Gawkowski stated that governmental institutions and security services maintain round-the-clock support for entities facing cyber threats, operating 24 hours a day.


