TUI Investigates Data Breach After Phishing Reports

Belgium Brief reports that travel company TUI is investigating a data breach after customers reported receiving suspicious messages containing personal details about their holidays. The messages allegedly included customers’ full names, hotel bookings and travel dates.
TUI has confirmed that it suffered a data breach, but the company has not yet established how many customers may have been affected or exactly what information was exposed.
TUI Warns Customers About Suspicious Messages
TUI spokesperson Piet Demeyere said an international team is investigating the incident to determine how the breach occurred and how many customers could be affected.
The company has contacted its customers and advised them to remain alert.
“We have sent a message to all customers asking them not to open suspicious messages and not to make any payments,” Demeyere told VTM Nieuws. He added that TUI hopes to provide more information as soon as possible.
Customers Report Messages Containing Travel Details
Some travellers have reported receiving unexpected WhatsApp messages from unknown senders.
According to reports received by Belgian newspaper HLN, some messages contained personal information, including the recipient’s full name, booked hotel and exact travel dates.
One customer said they contacted a local TUI office and were told that the issue was already known. The customer also claimed that other travellers had received similar messages the previous week.
Other customers reportedly received messages from numbers associated with Brazil or the United Kingdom. One person said the message included their name, departure and return dates, and the price of their holiday.
However, TUI has not confirmed whether the information described in these reports came directly from the data breach under investigation.
What Should TUI Customers Do?
Until more details become available, customers should take precautions when receiving unexpected messages about their holidays.
TUI customers should:
- Avoid opening suspicious links or attachments.
- Never transfer money in response to an unexpected message.
- Avoid sharing passwords, banking details or verification codes.
- Contact TUI through its official website or a verified customer service channel if they have concerns.
- Be cautious even when a message contains accurate booking details, as this does not prove that the sender is legitimate.
Investigation Is Still Underway
TUI has not yet disclosed the full extent of the incident. The investigation is expected to establish where the breach originated, what data may have been exposed and how many customers could be affected.
For now, the reports of targeted phishing messages raise concerns about the possible misuse of travellers’ personal information. However, the exact link between these messages and TUI’s confirmed data breach remains unverified.
Belgium Brief will follow developments as further information becomes available.

