Yes — Secureholiday, a French online camping-reservation platform run by the company Ctoutvert, was hacked, and personal data tied to 41,577 Dutch bookings was stolen. Secureholiday handles reservations for hundreds of European campgrounds, so the theft exposed real names, contact details, and trip plans to criminals. The good news is narrow but important: no payment-card or bank details were taken. According to the NL Times report on the breach, the stolen records covered bookings made between October 2025 and the end of February 2026, and the incident is already being used to target victims with convincing scam emails.
Table of Contents
- What exactly was stolen, and from whom
- Why "no card numbers" does not mean "no risk"
- How much actual fraud has happened
- What Secureholiday campers should do now
- Don't confuse this with the other 2026 Dutch breaches
- Frequently Asked Questions
What exactly was stolen, and from whom
Secureholiday is a booking system that campgrounds use to take online reservations. When you reserve a pitch through one of these sites, your details pass through this platform — which is why a single breach reached so many people at once. The NL Times reporting says the stolen data included names, email addresses, travel destinations, booking dates, and payment amounts. Notably, the criminals took the *amount* someone paid, but not the card used to pay it.
No payment-card or bank account numbers were compromised. The breach was discovered on 28 February 2026 and affected reservations at roughly 500 campgrounds, primarily in France, Spain, and Italy. The 41,577 figure counts Dutch bookings only, so the details of tens of thousands of other European campers were exposed as well. The real victim pool is far larger than the headline number.
Why "no card numbers" does not mean "no risk"
It is tempting to relax when card data stays safe. Here the opposite is true, because the stolen information is exactly what makes a scam believable. Criminals used the data to send phishing emails in May and June 2026, according to Cybernews. Phishing means fake messages designed to trick you into handing over money or credentials.
These emails impersonated the campgrounds, cited the victim's real booking details, and asked them to "confirm" their credit-card payment. That combination is dangerous. A message that names your actual campground, your dates, and the sum you paid does not look like spam — it looks like your booking. The breach did not leak your card, but it gave scammers a script to get you to type it in yourself.
How much actual fraud has happened
So far, the measurable harm is small relative to the exposure. Cybernews reports that 14 campers officially reported being defrauded, including 6 Dutch victims. That gap between tens of thousands exposed and 14 confirmed frauds is worth understanding.
It suggests most people spotted the scam or were never targeted — but it can also undercount, since victims often stay quiet or do not connect a scam email back to a campground booking. Treat 14 as a floor, not a final tally. The phishing campaign ran months after the February discovery date. That lag is normal: stolen data is often sold, sorted, and weaponized well after a breach, so vigilance should not fade just because the news cycle has.
What Secureholiday campers should do now
If you booked a European campground between October 2025 and February 2026, assume your contact and trip details may be in criminal hands. Focus your attention on any message that references that booking and asks for payment.
- Treat any "payment confirmation" email or text about your reservation as suspect, even when it quotes correct booking details.
- Never pay or re-enter card details from a link in an email; instead, contact the campground directly using a phone number or website you find independently.
- Check whether a message creates urgency ("confirm within 24 hours or lose your pitch") — that pressure is a classic scam signal.
- Watch the sender address for small misspellings of the campground or platform name.
- If you already clicked and entered card details, call your bank to block the card and dispute any charges.
Don't confuse this with the other 2026 Dutch breaches
This incident is separate from concurrent 2026 breaches at Booking.com and at more than 100 Dutch hotels. It is easy to blur them together because all involve travel bookings and Dutch victims in the same year.
The distinction matters for your response. The source of *this* leak is Secureholiday/Ctoutvert, as DutchNews.nl reporting on the hotel breach helps clarify. If you receive a scam email, matching it to the right breach helps you judge which of your details the sender actually holds — and which they are only guessing.
Frequently Asked Questions
Was my credit card number stolen in the Secureholiday breach?
No. Reporting indicates names, emails, destinations, booking dates, and payment amounts were taken, but not card or bank account numbers.
I booked a French campsite last winter but never heard anything. Am I affected?
Possibly. The 41,577 figure counts Dutch bookings only; around 500 campgrounds across France, Spain, and Italy were involved, so other Europeans were exposed too.
A campground emailed asking me to confirm my card. Is it real?
Be very skeptical. Scammers sent emails in May and June 2026 quoting real booking details; verify by contacting the campground through a number you find yourself.
