2026 Pierre & Vacances — Center Parcs — ~1.6M booking records leaked; criminal claims ~4M+ people (May)
Data compromised
Names, dates of birth, phone numbers, booking/stay details; emails and payment cards described as out of scope in early corporate statements
Technical writeup
On 14 May 2026, the Pierre & Vacances — Center Parcs (PVCP) group confirmed a cyberattack against a booking platform tied to its Maeva / “La France du Nord au Sud” ecosystem, with French press (Le Figaro, Sud Ouest, IT-Connect) summarizing official statements that roughly 1.6 million reservation records were exposed—some bookings dating back roughly twenty years. PVCP said email addresses and bank card data were not compromised in its initial characterization, while exposed categories included guest names, dates of birth, phone numbers, and detailed stay metadata useful for targeted voice phishing ahead of the summer holiday season. A criminal actor marketing on underground channels claimed data on more than four million individuals—a higher figure PVCP framed as plausible because multiple guests can appear on one reservation. The group filed a complaint, began customer notifications, and continued forensic review at catalog time.
Root cause
Security flaw exploited on a group booking subsidiary site (per press summaries); precise CVE/path not fully detailed in initial reporting
References
- https://www.lefigaro.fr/secteur/high-tech/1-6-million-de-reservations-et-10-ans-de-donnees-le-groupe-pierre-vacances-center-parcs-victime-d-une-cyberattaque-20260515
- https://www.it-connect.tech/pierre-vacances-center-parcs-hacked-1-6-million-booking-records-exposed/
- https://www.sudouest.fr/economie/cybersecurite/pierre-et-vacances-center-parcs-1-6-million-de-reservations-concernees-par-une-fuite-de-donnees-29081087.php