UMC Utrecht reports data breach in guesthouse reservation system
There’s no need to panic: no health-related data was exposed.

UMC Utrecht. PixelBiss / Shutterstock
- UMC Utrecht reported a data breach affecting about 5,000 guesthouse guests after a supplier’s booking system was hacked.
- The stolen data included contact details and booking information, but no financial, patient, or health-related records.
- UMC Utrecht warned affected guests to watch for scam messages, especially fake requests for advance digital payment.
- The supplier blocked external access, reset credentials, added monitoring, and hired cybersecurity investigators after the breach.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The University Medical Center Utrecht (UMC Utrecht) has reported a data breach to the authorities, affecting approximately 5,000 people.
The breach occurred on August 2nd, 2026, at VIPS PMS, a property management system supplier. The software is being used to run the booking system at the hospital’s guest house. The incident was reported on August 6th.
According to UMC Utrecht, the hacker exfiltrated personal details of past, present, and future guests, including names, home addresses, email addresses, phone numbers, gender, and booking information, such as arrival and departure dates.
No financial data, patient data, or other health-related information has been affected. Because of this, the hospital says that the risk of the data breach is limited. However, the exfiltrated information could potentially be misused to scam people via email, text message, telephone, or WhatsApp.
All affected guests have been informed by email. On top of that, the incident has been reported to the Dutch data protection authority.
Once the breach was discovered, the third-party supplier called in an external cybersecurity firm to investigate how the attacker gained access to bookings and the associated personal data of guests staying at the guest house.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
To prevent recurrence, VIPS PMS immediately blocked relevant external access, reset login credentials, secured all data related to the incident’s investigation, enabled additional checks and activity registration in the system, and implemented additional security measures.
“We ask you to be extra vigilant for unexpected messages regarding your stay or payment. UMC Utrecht never asks guests of the guesthouse to pay digitally in advance. You pay for your stay immediately upon check-out. We also do not ask for payment details via email or WhatsApp,” UMC Utrecht recommends.
A spokesperson confirmed to local news outlet RTV Utrecht that approximately 5,000 guests have been affected by the breach.