Croatian hotel reservation hack exposes data of 100,000 guests
A cyber‑attack targeted the reservation application used by major Croatian hotel chains, resulting in the theft of personal data belonging to more than 100,000 guests. After the breach, attackers sent WhatsApp messages to affected customers attempting to extort money, although no financial account details were compromised.
The incident has been reported to Croatia's Agency for Personal Data Protection (AZOP), which said it has received multiple reports from hotel groups and will conduct oversight that could last several months. Cyber‑security expert Marko Gulan warned that the breach highlights weaknesses in the tourism sector's cyber‑defences and noted that the sector is not yet required to comply with the national cyber‑security law, which will take effect by the end of 2027.
Authorities suspect the same Serbian‑based hacking group that previously breached the Dinamo football club and the Ministry of Labour, citing the use of nationalist messages in those attacks. The group has publicly identified itself, prompting calls for heightened security measures across Croatian businesses.