← Blog

Amadeus iHotelier Breach: Hotel Guest Data Exposed

Share on X

Amadeus IT Group confirmed unusual activity on an API tied to its iHotelier hospitality booking platform on 11 September 2026, according to a company spokesperson quoted by German trade outlet Tageskarte. Client hotels — including Germany’s Maritim Hotelgesellschaft — later told guests that reservation lists with contact and stay details had been stolen. Payment cards, passwords, and passport data were not in the exposed set, hotels and Amadeus say. There is still no global guest census from Amadeus; Maritim alone sent 8,716 notification emails on 17 September.

What happened

iHotelier is Amadeus’s central reservation / booking-engine stack that many hotels use for direct website bookings and inventory distribution. In mid-September, hotel operators began mailing guests about a Datenschutzvorfall at that vendor. Maritim’s managing director, Roland Elter, told trade press the incident involved service provider iHotelier of Amadeus IT Group S.A., that Amadeus secured the system after detection, and that guest data was nonetheless taken.

Amadeus’s own public comment, relayed by Tageskarte, is careful: unusual API activity on 11 September, immediate containment, a “very limited number” of hotel customers informed. How many hotels, and how many total guests worldwide, remains unpublished. That is why BreachHistory records recordsAffected: 0 on the Amadeus vendor row while cataloguing Maritim’s 8,716 emailed guests as an attested lower bound.

French properties such as 7Hotel & Spa in Illkirch-Graffenstaden also told guests Amadeus had confirmed unauthorized access to reservation data, according to secondary breach registers summarizing hotel notices. The pattern matches a vendor-side intrusion with multi-tenant blast radius — not a one-off hotel website defacement.

Timeline

  • 11 September 2026 — Amadeus detects unusual activity on an API connected to iHotelier (spokesperson to Tageskarte).
  • 17 September 2026 — Maritim emails 8,716 guests and reports to its supervisory authority under GDPR Article 33.
  • ~20–25 September 2026 — Trade and consumer travel coverage (HOGAPAGE, Hotel vor9, Travel Extra) summarizes the Amadeus / Maritim notices; additional hotels surface in local reporting.
  • 11 October 2026 — Indexed on BreachHistory as a verified Amadeus IT Group incident with linked Maritim customer impact.

Intrusion start date before 11 September is not published. Maritim’s guest letter cites possible impact for reservations with stays from 1 August 2026 through 30 September 2027 — a forward-looking booking window that matters for phishing, not a claim that attackers sat in the system that entire period.

What data was exposed — and what was not

Across Maritim’s letter and spokesperson clarifications, the inventory looks like classic CRS extract material:

  • Guest names
  • Email addresses and phone numbers
  • Postal addresses (Maritim described addresses without street in one spokesperson summary)
  • Reservation / booking reference numbers
  • Stay metadata: hotel, room category, rates/costs, arrival and departure dates, sometimes travel-agency fields

Not exposed, per Amadeus and Maritim: payment and financial data, passwords, and passport or ID-document data. That boundary is important. Travellers should still expect highly targeted phishing — a fake “confirm your deposit for check-in on 14 March” message that knows the real hotel and dates is more dangerous than a generic malware blast — but the incident is not a card-dump story on current evidence.

Amadeus has not published a field-by-field master inventory for every hotel customer. If you receive a notice from your property, treat that hotel’s letter as authoritative for your stay.

Who is at risk

Guests of iHotelier-powered hotels who held or hold reservations in the windows named by their hotel. Maritim guests with stays in the Aug 2026–Sep 2027 window are the clearest attested cohort. Guests of other Amadeus hospitality customers may also be in scope if their hotel sends a notice — absence of an email is not proof of safety if postal mail is still going out.

Hotel operators using iHotelier for direct bookings face brand and regulatory fallout even when the intrusion sat at the vendor. Maritim’s GDPR Art. 33 filing is the template: notify the DPA, notify guests, document the vendor conversation.

Travel agents and corporate travel desks that book Maritim or other affected hotels should warn travellers not to pay “rebooking fees” via WhatsApp.

How the attack worked (what is known)

Public detail stops at “unusual activity” on an API associated with iHotelier. There is no published CVE, no ransomware brand, and no claim of encryption. Amadeus’s framing points to API abuse or anomalous integration traffic rather than a classic malware outbreak on hotel PCs.

That matches how modern CRS platforms fail: overly permissive API keys, broken object-level authorization on reservation list endpoints, or compromised partner credentials that look like legitimate traffic until volume spikes. None of those mechanisms is confirmed here — they are the hypothesis space defenders should audit while waiting for a fuller post-mortem.

Maritim told reporters the exact access path was still unclear while talks with Amadeus continued. Do not invent a root cause beyond Amadeus’s API-activity statement.

Industry context

Hospitality has lived through a string of reservation-data incidents — from mega-brand CRM breaches to smaller PMS vendors. What makes an Amadeus iHotelier event different is concentration risk: one booking engine sits behind many hotel brands’ “Book direct” buttons. A single API compromise can fan out across countries without each hotel’s website being hacked individually.

Separately, Spain’s AEPD fined Amadeus in 2026 over the PLATAFORMA.1 traveller-profiling pilot (GDPR transparency / lawful-basis issues). That enforcement is about internal reuse of passenger data, not this September cyber incident. Keep them distinct when answering questionnaires.

Also keep Quest Apartment Hotels’ August 2026 ~1.99M-customer breach in a different bucket. Quest described an unnamed third-party software vulnerability; Quest has not publicly named Amadeus in the notices BreachHistory cites. Do not merge those censuses.

What Amadeus, Maritim, and regulators said

Amadeus: detection on 11 September, containment, limited hotel customers informed, exposed information characterized as contact-related rather than financial (via Tageskarte).

Maritim: confirmed the vendor incident, apologized for the data theft, emailed 8,716 guests on 17 September, filed with the competent data-protection authority, and warned guests about phishing.

No Amadeus global headcount or securities filing detailing guest totals was attached at indexing. If Amadeus later publishes a hospitality customer advisory with numbers, the catalog row should be updated.

Action items

  1. If you get a hotel email about iHotelier / Amadeus, read it — then verify payment instructions only through the hotel’s official phone number or logged-in account, never via links in the notice thread.
  2. Expect WhatsApp and SMS lures that quote your real arrival date and rate. Hang up and call the front desk.
  3. You do not need to replace passports based on Maritim/Amadeus statements for this incident; those fields were excluded.
  4. Still monitor cards if you reused the same email/password elsewhere — password reuse is a separate risk.
  5. Hotel IT: rotate iHotelier API credentials, review reservation-list export permissions, and ask Amadeus for tenant-level indicators of compromise.
  6. Corporate travel managers: push a one-paragraph advisory to frequent travellers booked into Maritim or other notified brands.
  7. Ignore “Amadeus security invoice” PDFs from unknown domains.
  8. Canonical vendor record: Amadeus iHotelier 2026; Maritim impact: Maritim Hotels.

Canonical record and sources

Primary trade sources: Tageskarte (Amadeus spokesperson + Maritim confirmation), Hotel vor9, HOGAPAGE, and Travel Extra. Relative catalog links: /amadeus-it-group/amadeus-ihotelier2026 and /maritim-hotels/maritim-hotels-ihotelier2026.

Phishing playbook attackers are likely to use

Reservation-detail theft is phishing fuel. A message that knows your surname, hotel, and check-in date bypasses the scepticism people apply to generic “your parcel is waiting” spam. Typical lures after CRS leaks include: “Your guarantee card failed — pay within 2 hours or we cancel,” “Tourist tax unpaid,” and “Loyalty upgrade: confirm IBAN.” None of those should arrive as a cold WhatsApp from a mobile number.

Call centres at affected hotels should script agents to never collect card data from inbound callers who reference the breach email. Fraudsters will social-engineer both sides of the conversation.

Email authentication (DMARC) on hotel domains helps, but lookalike domains (maritim-booking-secure, amadeus-guest-verify) will still appear. Teach staff to check the registered domain, not the display name.

For security and procurement teams

If Amadeus Hospitality / iHotelier is in your stack, open a vendor ticket asking: which tenants were in scope, which API clients showed anomalies, whether reservation exports were bulk-downloaded, and whether partner SSO tokens were rotated. Ask for written confirmation that payment token vaults were out of scope — matching the public statements.

Update your DPIA / RoPA entries for guest booking data processed by Amadeus. Document the 11 September detection date and your hotel’s notification decision under GDPR (or UK GDPR / local hotel laws). Boards will ask why “limited customers” still produced thousands of guest emails at a single brand.

When completing security questionnaires, cite the Amadeus spokesperson date and Maritim’s 8,716 figure separately from Quest’s 1.99M census. Mixing those numbers is how bad risk reports get written.

Comparing Amadeus iHotelier to other 2026 travel breaches

Quest Apartment Hotels’ August incident involved a third-party database with passport numbers and credit-card CVVs for subsets of ~1.99M Australian customers — a harsher data mix than the Amadeus/Maritim notices describe. Booking.com’s 2026 guest-reservation access case similarly stressed phishing risk without card dumps. The Amadeus iHotelier story sits closer to the Booking.com pattern: reservation graph exposure, vendor or platform adjacency, heavy social-engineering aftermath.

Readers searching “Amadeus data breach 2026” may also hit GDPR fine coverage. That AEPD case is about profiling pilots and transparency, not API intrusion. Link both in diligence folders; do not collapse them into one incident ID.

If more hotel brands publish headcounts, BreachHistory will revise the Amadeus row’s recordsAffected upward from zero. Until then, “confirmed intrusion, unpublished global census” is the accurate summary.

Was I affected?

You may be affected if a hotel that uses Amadeus iHotelier for direct bookings contacts you, or if you held a Maritim reservation in the stay window named in Maritim’s letter. There is no public Amadeus lookup tool. Do not upload passport scans to random “breach check” sites advertising this incident.

If you never booked through an iHotelier-powered hotel site or Maritim property, this Amadeus IT Group breach is background intelligence, not a personal emergency. Still worth understanding if you work in travel procurement.

Operational notes for hotel CISOs

Treat Amadeus’s “limited customers” language as a scoping statement, not a comfort blanket. Limited hotel tenants can still mean tens of thousands of guests. Inventory every brand and franchise that points its booking engine at iHotelier, including white-label domains that do not say “Amadeus” in the browser chrome.

Log reviews should focus on reservation search and export APIs between early September and containment. Look for user-agents or IP ranges that pulled full stay lists rather than single booking lookups. Preserve those logs before rotation policies wipe them.

Guest communications should be boring and specific: what fields, what stay window, what will never be asked for by phone. Over-promising (“your data is 100% safe now”) invites regulatory pain if another wave of notices follows.

Franchisees sharing a CRS tenant with a notified brand should assume shared risk until Amadeus says otherwise in writing. Quietly rotating API secrets is cheaper than explaining a second guest mailing to ownership groups.

Additional researcher notes

Open-source collectors should preserve hotel notice PDFs and trade interviews without republishing guest PII samples. Cite Tageskarte for the Amadeus spokesperson date and Maritim’s 8,716 figure. Revisit the Amadeus catalog row if a global hospitality advisory lands with an attested census.

Procurement teams can use this Amadeus data breach as a tabletop: map every booking widget that posts to Amadeus endpoints, confirm who owns guest notification duty under your DPAs, and pre-draft the guest email that refuses to collect cards by reply.

Additional researcher notes

Open-source collectors should preserve hotel notice PDFs and trade interviews without republishing guest PII samples. Cite Tageskarte for the Amadeus spokesperson date and Maritim’s 8,716 figure. Revisit the Amadeus catalog row if a global hospitality advisory lands with an attested census.

Procurement teams can use this Amadeus data breach as a tabletop: map every booking widget that posts to Amadeus endpoints, confirm who owns guest notification duty under your DPAs, and pre-draft the guest email that refuses to collect cards by reply.

Additional researcher notes

Open-source collectors should preserve hotel notice PDFs and trade interviews without republishing guest PII samples. Cite Tageskarte for the Amadeus spokesperson date and Maritim’s 8,716 figure. Revisit the Amadeus catalog row if a global hospitality advisory lands with an attested census.

Procurement teams can use this Amadeus data breach as a tabletop: map every booking widget that posts to Amadeus endpoints, confirm who owns guest notification duty under your DPAs, and pre-draft the guest email that refuses to collect cards by reply.

Additional researcher notes

Open-source collectors should preserve hotel notice PDFs and trade interviews without republishing guest PII samples. Cite Tageskarte for the Amadeus spokesperson date and Maritim’s 8,716 figure. Revisit the Amadeus catalog row if a global hospitality advisory lands with an attested census.

Procurement teams can use this Amadeus data breach as a tabletop: map every booking widget that posts to Amadeus endpoints, confirm who owns guest notification duty under your DPAs, and pre-draft the guest email that refuses to collect cards by reply.

Additional researcher notes

Open-source collectors should preserve hotel notice PDFs and trade interviews without republishing guest PII samples. Cite Tageskarte for the Amadeus spokesperson date and Maritim’s 8,716 figure. Revisit the Amadeus catalog row if a global hospitality advisory lands with an attested census.

Procurement teams can use this Amadeus data breach as a tabletop: map every booking widget that posts to Amadeus endpoints, confirm who owns guest notification duty under your DPAs, and pre-draft the guest email that refuses to collect cards by reply.