Important Security Notice

Last updated: 17 August 2026

We are providing information about a security incident involving the hotel software service provider used by our hotel.

According to the service provider, unknown attackers gained unauthorised access to its systems on 25 July 2026. Based on the current state of the investigation, personal data relating to hotels and their guests was obtained.

The service provider’s current public statement is available on the website of ibelsa GmbH. Please note that the statement is available in German.

The service provider is still unable to reliably determine which hotels, booking periods or specific records were affected. As a precaution, we must therefore assume that personal data relating to our guests and customers may also have been affected.

The incident remains under investigation with the assistance of external IT forensics and security experts.

Data that may have been affected

Based on the information currently available, the affected data may include:

  • names and contact details,
  • postal addresses, dates of birth and countries of origin,
  • email addresses and telephone numbers,
  • information about reservations and stays,
  • invoice and guest registration data, and
  • other information stored in connection with a booking.

According to the service provider, no payment data was obtained based on the current state of the investigation. Bank details and other payment data processed and stored outside the hotel software were also not affected.

We have only been using the affected hotel software since November 2025. Data from our previous hotel management system was not transferred. Older guests and customers can therefore only be present in the current system if a new booking was made or a new contact record was created on or after November 2025.

As the investigation has not yet been completed, the information concerning the scope of the incident may still change.

Please remain particularly vigilant

According to a data protection supervisory authority and DEHOGA, phishing and fraud attempts involving genuine booking data have already been identified. Fraudsters may contact guests by email, text message or WhatsApp while pretending to represent a hotel or booking platform.

These messages may contain the correct name, hotel, travel dates or other reservation details and may therefore appear particularly convincing. However, the inclusion of correct booking information does not prove that a message genuinely originates from us or from a booking platform.

Fraudulent messages may, for example, ask guests to make an urgent payment, enter payment or credit card details, or confirm a booking by following a link. In some cases, the fraudsters threaten to cancel the booking if the recipient does not comply.

Please observe the following precautions:

  • Check unexpected messages, links and payment requests relating to your booking particularly carefully.
  • Do not trust a message solely because it contains correct booking information.
  • Do not open suspicious links or use them to enter payment, credit card or login details.
  • Only make payments or change payment details through communication and payment channels that you already know and have verified.
  • Do not transfer money to an unfamiliar bank account or to an account communicated to you at short notice.
  • Do not allow yourself to be pressured by short payment deadlines or threats that your booking will be cancelled.
  • If in doubt, contact us exclusively using the official contact details published on our website.
  • If you have already provided payment or credit card details or made a payment, contact your bank or credit card provider immediately.
  • If you have entered login details or passwords, change the affected passwords immediately. Where appropriate, you should also report the incident to the police.

Information about our payment links

In certain cases, Garden Hotel Krefeld sends payment links through the booking and payment system used by our hotel.

Please carefully check the sender information and the web address displayed in every payment link. If you receive an unexpected payment request or if the sender, web address, bank details or content appear unusual, do not enter any payment details and do not make a payment.

In such cases, please contact us first by telephone at +49 (0) 2151 53523-0. We will be happy to confirm whether the payment request or payment link genuinely originated from us.

Further information on protecting yourself against fraud is available from the State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Western Pomerania and the German Consumer Advice Centre. Please note that these resources are available in German.

Measures taken by us

Immediately after becoming aware of the incident, we implemented additional security measures. These measures included:

  • changing all passwords for the hotel software,
  • changing the login credentials for the email accounts connected to the hotel software,
  • activating multi-factor authentication for all hotel software users,
  • reviewing user accounts and access permissions, and
  • reviewing relevant system connections and increasing their monitoring.

In addition, we directly notified guests and customers for whom we had email addresses, informed our employees about potential phishing and fraud attempts, and reported the incident to the data protection supervisory authority responsible for our hotel.

Based on the information currently available, we have no indication that Garden Hotel Krefeld’s own systems were directly attacked or compromised.

We are monitoring developments closely and will update this notice as soon as material new information becomes available.

Contact

If you have any questions or receive a suspicious message, please contact us:

Garden Hotel Krefeld
Wolfram Lawall e.K.
Schönwasserstraße 12A
47800 Krefeld
Germany

Contact person:
Steve Lawall
Telephone: +49 (0) 2151 53523-0
Email: datenschutz@gardenhotel.de