MARCH 2026: H Rewards Data Security Incident
The trust and security of guests are our top priority. This naturally also includes the protection of personal data.
Despite very high technical security standards, a temporary external data security incident occurred in March 2026. We have openly and transparently informed about this incident, the actions taken, and what this means.
Please be assured that we took this incident very seriously.
What happened?
As part of our regular monitoring of the hotel booking website and the H Rewards loyalty program, we identified an external access attempt affecting a limited part of our systems. As a result, personal data relating to some customers and H Rewards members may have been temporarily accessible.
The incident was detected early and immediately contained through technical measures.
Depending on the individual data record, the information potentially affected may have included name, contact details, date of birth, and address information.
Following completion of the forensic investigation, we can confirm that passwords, booking details, and payment information were not accessible.
What actions have been taken?
The identified vulnerability was closed immediately. In addition, a forensic investigation was conducted, and further security measures have been implemented.
The competent data protection supervisory authorities were also informed in accordance with legal requirements. Where possible, affected individuals were contracted directly. As not all records include an email address, we also published this information publicly in the interest of transparency and security.
How can I check if my data was affected?
To check whether your data may have been affected, please sned an emial to dataprivacy.rfi@hrewards.com. We kindly ask you not to contact us by telephone for this purpose.
What consequences could arise from the incident?
As with any incident involving personal data, it cannot be ruled out that information could be misused. We therefore generally recommend exercising increased caution in relation to unexpected messages, calls, or emails.
We have no information indicating whether the personal data was copied or only viewed. Should you have any indication that data has been misused, please report this immediately to dataprivacy.rfi@hrewards.com.
What should I be aware of?
Please note that neither H Rewards nor a hotel will ever ask you to provide your password, payment details, or any other sensitive personal information. If you receive such a request, please treat it as suspicious and do not respond. Please do not respond to emails, chat messages or phone calls asking you to confirm your booking and/or provide payment details and/or passwords.
To check the status of your booking, please log in to your H Rewards account or contact the H Rewards Service Center or the hotel directly.
In light of the overall increase in cyber threats, particular attention should be paid to the general principles for the secure use of digital media. Please be alert to suspicious communications from third parties and do not disclose any confidential information to unknown persons.
Who can I contact if I have questions or concerns?
If you have any further questions or concerns, please contact dataprivacy.rfi@hrewards.com.
In addition, you can contact the Data Protection Officer:
Steigenberger Hotels GmbH: TÜV Informationstechnik GmbH, Am TÜV 1, 45307 Essen, datenschutz@deutschehospitality.com
H Rewards Loyalty Program, H Rewards Pte. Ltd.: Wodianka privacy legal GmbH, Dockenhudener Straße 12a, 22587 Hamburg, eu-representative@hrewards.com