Polish travel agency Wakacje.pl has confirmed a significant data breach after hackers gained access to its customer service system and several employee email accounts, according to technology news site Spider’s Web.
The compromised information includes passport data, telephone numbers, home addresses, email addresses, full names and dates of birth. However, the company has not clarified the exact nature of the “passport data” obtained by the attackers, leaving uncertainty over whether this includes passport numbers, scans or other details.
Wakacje.pl has also not disclosed how many customers have been affected by the incident. Cybersecurity site Niebezpiecznik, which first reported the breach, noted that the company’s use of the term “passport data” rather than simply “passport numbers” suggests more comprehensive information may have been stolen.
Part of wider attack wave
The breach at Wakacje.pl forms part of what Spider’s Web describes as “catastrophic weeks” for data security in Poland. Recent attacks have targeted medical service providers MyDr, Medoc and accounting platform Fakturownia.pl, with health records among the sensitive information compromised.
Niebezpiecznik confirmed that the Wakacje.pl breach was not carried out by the hacker known as “fingerprint”, who was responsible for the recent attacks on medical and financial platforms. The attacker has reportedly stated they “do not intend to attack any more Polish companies”.
Piotr Konieczny from Niebezpiecznik argued that the Polish state shares responsibility for the spate of breaches. He pointed out that regulations did not require service providers handling medical or financial data to implement adequate monitoring systems for years. Although the NIS2 directive came into force in Poland on 3 April 2026, he questioned whether the recently targeted companies fall under its scope.
Government response
Following the attack on Fakturownia, Poland’s Minister for Digitalisation Krzysztof Gawkowski assured the public that “services responsible for security are reacting immediately” and that “perpetrators are being pursued and will face severe consequences”.
However, Gawkowski placed the burden of responsibility on private companies themselves, stating that recent attacks demonstrate the private sector must increase investment and effort in cybersecurity protection. He recommended businesses use the Cyber.gov.pl portal, which he described as a reliable source of support for improving cybersecurity standards, adding that support from state institutions and services is available around the clock.
Spider’s Web questioned whether the state should be doing more to enforce higher security standards rather than simply advising companies to improve voluntarily.
What this means for Poles in the UK
If you booked a holiday through Wakacje.pl, your personal information may have been compromised, even if you now live abroad. Passport details are particularly sensitive as they can be used for identity theft or fraud.
Check your email for communication from Wakacje.pl about the breach. Monitor your bank accounts and credit file for unusual activity. If you used the same password for Wakacje.pl as for other services, change it immediately. Consider placing a fraud alert on your credit file with UK agencies such as Experian, Equifax or TransUnion.
If your passport number was exposed, be vigilant for phishing attempts or identity fraud. While you cannot change a passport number unless you apply for a new document, knowing your details are compromised helps you spot suspicious activity. Report any fraud attempts to Action Fraud in the UK at actionfraud.police.uk or by calling 0300 123 2040.

