2026 Amadeus IT Group — iHotelier API intrusion; hotel reservation/contact data (no cards/passports)
Data compromised
Per hotel customer notices (e.g. Maritim, 7Hotel): guest names, contact details (email/phone; postal address often without street), reservation numbers, hotel/stay details (dates, rates, room category). Amadeus/hotels state payment/financial data, passwords, and passport/ID document data were not exposed. Global guest census unpublished (recordsAffected 0); Maritim alone emailed 8,716 guests.
Technical writeup
Verified Amadeus + hotel-customer confirmation — Amadeus spokesperson told Tageskarte the company detected unusual activity on 11 September 2026 on an API connected to iHotelier, contained/remediated the incident, and informed a “very limited number” of hotel customers (global guest headcount unpublished). Maritim Hotelgesellschaft confirmed a relevant data-protection incident at service provider iHotelier / Amadeus IT Group S.A., emailed 8,716 guests on 17 September 2026, and reported to its DPA under GDPR Art. 33. Stay window cited for Maritim reservations: 1 August 2026–30 September 2027. Exposed fields per guest letters/trade press: names, contacts, reservation and stay details; payment cards, passwords, and passport data excluded. French hotels (e.g. 7Hotel & Spa Illkirch-Graffenstaden) also notified guests citing Amadeus confirmation. Distinct from Quest Apartment Hotels’ Aug 2026 third-party breach (Quest has not publicly named Amadeus) and from Amadeus’s separate 2026 AEPD GDPR fine over PLATAFORMA.1 profiling (not a cyber intrusion). companyConfirmed true; recordsAffected 0.
Root cause
Unauthorized access via unusual activity on an API connected to the Amadeus iHotelier hospitality booking platform (detected 11 Sep 2026 per Amadeus spokesperson)
References
- https://www.tageskarte.io/hotellerie/detail/maritim-informiert-gaeste-ueber-datendiebstahl-bei-ihotelier.html
- https://www.hotelvor9.de/inside/datenpanne-bei-amadeus-betrifft-gaeste-von-maritim
- https://www.hogapage.de/nachrichten/netzwelt/web/maritim-informiert-tausende-gaeste-nach-datenpanne-bei-ihotelier/
- https://www.travelextra.ie/amadeus-ihotelier-booking-platform-suffers-security-breach/