← Pierre & Vacances — Center Parcs (PVCP)

2026 Pierre & Vacances — Center Parcs — ~1.6M booking records leaked; criminal claims ~4M+ people (May)

2026 4.0M records affected Share on X

Data compromised

Names, dates of birth, phone numbers, booking/stay details; emails and payment cards described as out of scope in early corporate statements

Technical writeup

On 14 May 2026, the Pierre & Vacances — Center Parcs (PVCP) group confirmed a cyberattack against a booking platform tied to its Maeva / “La France du Nord au Sud” ecosystem, with French press (Le Figaro, Sud Ouest, IT-Connect) summarizing official statements that roughly 1.6 million reservation records were exposed—some bookings dating back roughly twenty years. PVCP said email addresses and bank card data were not compromised in its initial characterization, while exposed categories included guest names, dates of birth, phone numbers, and detailed stay metadata useful for targeted voice phishing ahead of the summer holiday season. A criminal actor marketing on underground channels claimed data on more than four million individuals—a higher figure PVCP framed as plausible because multiple guests can appear on one reservation. The group filed a complaint, began customer notifications, and continued forensic review at catalog time.

Root cause

Security flaw exploited on a group booking subsidiary site (per press summaries); precise CVE/path not fully detailed in initial reporting

References