← Amadeus IT Group

2026 Amadeus IT Group — iHotelier API intrusion; hotel reservation/contact data (no cards/passports)

2026 Unknown records affected Share on X

Data compromised

Per hotel customer notices (e.g. Maritim, 7Hotel): guest names, contact details (email/phone; postal address often without street), reservation numbers, hotel/stay details (dates, rates, room category). Amadeus/hotels state payment/financial data, passwords, and passport/ID document data were not exposed. Global guest census unpublished (recordsAffected 0); Maritim alone emailed 8,716 guests.

Technical writeup

Verified Amadeus + hotel-customer confirmation — Amadeus spokesperson told Tageskarte the company detected unusual activity on 11 September 2026 on an API connected to iHotelier, contained/remediated the incident, and informed a “very limited number” of hotel customers (global guest headcount unpublished). Maritim Hotelgesellschaft confirmed a relevant data-protection incident at service provider iHotelier / Amadeus IT Group S.A., emailed 8,716 guests on 17 September 2026, and reported to its DPA under GDPR Art. 33. Stay window cited for Maritim reservations: 1 August 2026–30 September 2027. Exposed fields per guest letters/trade press: names, contacts, reservation and stay details; payment cards, passwords, and passport data excluded. French hotels (e.g. 7Hotel & Spa Illkirch-Graffenstaden) also notified guests citing Amadeus confirmation. Distinct from Quest Apartment Hotels’ Aug 2026 third-party breach (Quest has not publicly named Amadeus) and from Amadeus’s separate 2026 AEPD GDPR fine over PLATAFORMA.1 profiling (not a cyber intrusion). companyConfirmed true; recordsAffected 0.

Root cause

Unauthorized access via unusual activity on an API connected to the Amadeus iHotelier hospitality booking platform (detected 11 Sep 2026 per Amadeus spokesperson)

References