Polish travel portal Wakacje.pl warned customers after a cyberattack on September 29, 2026 compromised a customer-service system and several employee email accounts, TVP World reported (citing Niebezpiecznik). Attackers reportedly obtained names, dates of birth, phones, addresses, emails, and passport details. The portal advised watching for fraudulent payment requests and considering passport cancellation. Nationwide headcount unpublished — recordsAffected 0.
Canonical: https://breachhistory.com/wakacje-pl/wakacje-pl2026.
What happened
Company-to-customer messaging plus specialist-press reporting make this a verified incident narrative. Wakacje says more than a million customers book holidays/tickets yearly — that is marketing scale, not an attested breach census.
Action items
- Treat payment-change SMS as hostile.
- Consider passport reissue guidance from Polish authorities if you booked recently.
- Rotate passwords reused on Wakacje.
- Monitor bank cards used for bookings.
Sources
Open questions and verification posture
Week-one reporting rarely includes full malware forensics. Separate victim/regulator facts from actor marketing. Missing headcounts stay zero in the catalog until a filing appears. That discipline keeps BreachHistory usable when headlines inflate.
Phishing to expect
Lookalike domains, fake incident-response WhatsApp accounts, and urgency around fake enrollment deadlines. Call numbers printed on official letters only. Do not install remote-support tools from cold callers. Do not pay crypto to strangers.
Neighboring incidents
Cross-read related BreachHistory finance, education, healthcare, and ransomware-claim posts for pattern recognition — shared vendor risk and delayed consumer mailings recur through 2026. Use comparisons for briefings, not to copy unverified counts across rows.
Security-team checklist
- Inventory non-core systems holding identifiers.
- Phishing-resistant MFA on those systems.
- Log/alert bulk exports.
- Pre-draft counsel-approved notices.
- Tabletop a 72-hour extortion email with legal and PR.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.
Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.