Major Cyberattacks Expose Weaknesses in France's Tourism Sector Security
A recent wave of cyberattacks on leading French tourism companies highlights significant cybersecurity flaws affecting millions of customers' personal data.
- • Gîtes de France data breach impacted over 389,000 clients, traced to IT provider Itea.
- • The hacker claimed responsibility for three attacks on major tourism companies within three days.
- • Compromised data included names, reservations, emails, and contact details but no banking information.
- • All affected companies plan to file complaints amid investigations revealing cybersecurity weaknesses in France.
Key details
French tourism companies Gîtes de France, Pierre et Vacances-Center Parcs, and Belambra have all suffered significant cyberattacks within the past three days, exposing serious vulnerabilities in France's cybersecurity landscape. Gîtes de France revealed on May 17, 2026, that over 389,000 customer records were compromised in a breach traced back to their IT service provider Itea. The stolen data included client names, reservation dates, emails, phone numbers, and postal addresses, but no banking information was accessed. This breach affected reservations spanning more than 30 years, from 1995 to 2026, and was limited to specific French departments.
The same hacker claimed responsibility for this and two other attacks targeting Pierre et Vacances-Center Parcs and Belambra. Pierre et Vacances reported 1.6 million reservations affected, while Belambra disclosed a breach involving over 41,000 detailed reservations alongside about 360,000 records related to minors. No financial data was reportedly stolen in these attacks.
The attacker stated that the motive behind these breaches was to illustrate the fragility of France's cybersecurity defenses, dubbing the country a "cybersecurity sieve." The repeated incidents within France's top tourism operators have prompted all three companies to file official complaints as investigations continue.
These events highlight growing concerns over cybersecurity readiness within France's tourism sector and question the robustness of national protective measures. The breaches expose millions of reservation records and personal customer details, raising alarms about the lasting impact on consumer trust and data protection standards in one of France's vital economic sectors.
This article was translated and synthesized from French sources, providing English-speaking readers with local perspectives.
Source articles (2)
Source comparison
Number of affected reservations at Belambra
Sources report different numbers of affected reservations at Belambra
lemonde.fr
"Belambra's breach involved 1.6 million reservations."
cnews.fr
"Belambra also reported a security incident, which compromised over 41,000 detailed reservations."
Why this matters: One source states that Belambra's breach affected over 41,000 detailed reservations, while the other mentions 1.6 million reservations. This discrepancy significantly alters the understanding of the scale of the breach at Belambra.
Latest news
Experts Highlight Gap Between French Government Proposals and Economic Realities
G7 Finance Ministers Meet in Paris to Tackle Economic Fallout from Middle East Conflict
Tour de France 2028 to Start in Reims with Multiple Stages in Grand Est Region
French Ultramarine Economies Oppose EU Carbon Border Adjustment Amid High Costs and Environmental Concerns
Canal+ CEO Cuts Ties with Cinema Professionals Amid Anti-Bolloré Backlash
French Senate Launches Inquiry into Private Funding of Public Policies
The top news stories in France
Delivered straight to your inbox each morning.