TUI investigates leak after targeted WhatsApp fraud
The travel organisation does not yet know how many customers were affected or what data was taken.
Listen to this article
There is no audio version yet. Request one and an AI voice will read the article aloud.
Read by an AI voice.
TUI is investigating a data breach after customers received messages containing their name, hotel and travel dates. The travel organisation confirms that data was exposed, but says it does not yet know how the breach occurred or how serious the consequences are.
TUI Belgium confirmed to Belgian media that the company had fallen victim to a data breach. The scale of the incident and the precise data taken had not yet been established on Sunday. It is therefore also unclear whether TUI’s Dutch operation was affected by the same incident.
The messages received by customers reportedly followed a recognisable pattern. WhatsApp messages used, among other things, names, hotel details and exact holiday dates. Customers were led to believe that their booking had to be confirmed again or that their trip would otherwise be cancelled.
The messages referred to a fraudulent link. TUI says the company does not ask customers for payment via WhatsApp and advises travellers to check their booking only through official websites or customer channels. The organisation is still investigating whether the information came from a TUI system or was obtained through a supply-chain partner.
That distinction matters. A phishing campaign can use data leaked somewhere in a booking chain without the travel organisation’s central systems themselves having been hacked. At present, according to the available reporting, there is no evidence that attackers had access to all TUI systems.
The case shows why travel data is attractive to fraudsters. A message containing a real destination and travel date inspires more trust than a general fake email. At the same time, recognisable information on its own does not show how the data was obtained or how many people were involved.
The Belgian Data Protection Authority writes that organisations must in principle report a personal-data breach without undue delay and, where possible, within 72 hours. That is a general rule and does not confirm that TUI exceeded that deadline. The immediate responsibility now lies with TUI to establish the source of the breach, the data leaked and the customers affected.
One story, several perspectives
What is established
- TUI is investigating a data breach.
- Customers were approached with travel data in WhatsApp messages.
- The source and scale of the incident have not yet been established.
Left
Arguments Travel organisations collect highly sensitive and detailed movement data and must therefore apply stricter security and report data breaches more quickly.
Values Privacy, consumer protection and the balance of power between companies and customers.
Consequences More oversight and higher security costs may be necessary, but would reduce the damage caused by targeted fraud.
Centre
Arguments The rules already exist; the priority should be careful investigation, clear communication with customers and proportionate enforcement once the facts have been established.
Values Legal certainty, proportionality and reliable information.
Consequences Prematurely accusing TUI could harm the investigation, while delayed communication would expose customers to further fraud.
Right
Arguments Companies should bear primary responsibility for their digital security and the costs of negligence. Customers should meanwhile be cautious with links and payment requests.
Values Personal responsibility, liability and entrepreneurial freedom.
Consequences Greater liability could encourage security, but additional obligations could place a relatively heavy burden on smaller travel companies.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The text clearly distinguishes between a confirmed data breach and an unproven hack of TUI systems. The general GDPR reporting deadline was checked with the Belgian regulator.
- confirmed TUI Belgium has confirmed a data breach and is investigating its scale. — Reported by Nieuwskoppen.be on the basis of statements to HLN and VTM Nieuws. source
- confirmed Customers received WhatsApp messages containing names, hotels and travel dates. — Summary of reporting by Sudinfo.be. source
- confirmed There is no evidence that TUI’s central systems were hacked. — The reporting consulted says that the source of the data is unknown and that no hack of TUI systems has been established. source
- confirmed A personal-data breach must in principle be reported within 72 hours where possible. — General explanation by the Belgian Data Protection Authority. source
Editor's note
TUI has confirmed a data breach, but its scale, source and any impact in the Netherlands remain unknown. Reporting about WhatsApp messages confirms the fraud context, not that TUI systems themselves were hacked.Sources
- Reisoperator TUI slachtoffer geworden van datalek — Nieuwskoppen.be, met verwijzing naar Het Belang van Limburg
- TUI customers targeted by WhatsApp scam using personal travel details — News Minimalist, samenvatting van Sudinfo.be
- Een gegevensinbreuk melden en beheren — Belgische Gegevensbeschermingsautoriteit
- Privacy-overeenkomst TUI Belgium — TUI Belgium
More on this in Dutch media
- Het Parool — „tui datalek”
- NRC — „tui datalek”
- Tweakers — „tui datalek”