Croatian hotel reservation platform Phobs data breach affects ~100,000 tourists
The reservation system Phobs, used by major Croatian hotel chains, suffered a security incident that exposed personal details of roughly 100,000 guests planning summer stays on the Adriatic coast. Leaked information includes names, phone numbers, arrival and departure dates, and the hotels booked.
Fraudsters have used the data to send convincing WhatsApp messages that appear to come from the hotels, urging recipients to confirm their reservation or provide credit‑card details for an alleged additional payment. The messages contain accurate reservation details, making the phishing attempts highly credible.
Hotel groups such as Valamar, Maistra, Zaton Holiday Resort and Aminess have warned guests not to click any links or share payment information via WhatsApp, and to verify any requests through official channels. Croatia’s data‑protection authority (AZOP) has issued the same advisory, noting that no financial data were compromised and that the breach was not caused by a database hack or unauthorized system intrusion. Phobs said it acted immediately to secure its systems and is cooperating with authorities.
The incident highlights a broader European trend of “reservation hijack” scams, following earlier breaches affecting Booking.com users. Authorities continue to monitor the situation and advise travelers to remain vigilant.