H Rewards Data Security Incident Update
The trust and security of guests are our top priority. This naturally also includes the protection of personal data.
Despite very high technical security standards, a temporary external data security incident occurred in March 2026. We are informing you openly and transparently about this incident, the actions taken, and what this means for you.
We fully understand that this news may cause concern and raise questions. Please be assured that we are taking this incident very seriously.
What happened?
As part of our regular monitoring of the hotel booking website and the H Rewards loyalty program, we identified an external access attempt affecting a limited part of our systems. As a result, personal data relating to some customers and H Rewards members may have been temporarily accessible.
The incident was detected early and immediately contained through technical measures.
Depending on the individual data record, the information potentially affected may include name, contact details, date of birth, and address information.
Following completion of the forensic investigation, we can confirm that passwords, booking details, and payment information were not accessible.
What has been done?
The identified vulnerability was closed immediately. In addition, a forensic investigation was conducted, and further security measures have been implemented.
The competent data protection supervisory authorities were also informed in accordance with legal requirements. Where possible, affected individuals were contracted directly. As not all records include an email address, we are also publishing this information publicly in the interest of transparency and your security.
How can I check if my data was affected?
To check whether your data may have been affected, please use only the online form "Data Security Self-Check". Please note that this check can only be carried out via the online form. We kindly ask you not to contact us by telephone for this purpose.
What consequences could arise from the incident?
As with any incident involving personal data, it cannot be ruled out that information could be misused. We therefore generally recommend exercising increased caution in relation to unexpected messages, calls, or emails.
What should I be aware of?
Please note that H Rewards will never ask you to provide your password, payment details, or any other sensitive personal information. If you receive such a request, please treat it as suspicious and do not respond.
In light of the overall increase in cyber threats, particular attention should be paid to the general principles for the secure use of digital media. Please be alert to suspicious communications from third parties and do not disclose any confidential information to unknown persons.
What impact does this have on bookings and hotel operations?
The incident has no impact on existing or future hotel bookings. Business operations at all hotels were not and are not affected.
What happened to the data?
We have no information indicating whether the personal data was copied or only viewed. Should you have any indication that data has been misused, please report this immediately to dataprivacy.rfi@hrewards.com.
Ongoing commitment
We take this incident very seriously. The protection of personal data and continuous enhancement of security measures remain a top priority.
Who can I contact if I have questions or concerns?
If you have any further questions or concerns, please contact dataprivacy.rfi@hrewards.com.
In addition, you can contact the Data Protection Officer:
Steigenberger Hotels GmbH: TÜV Informationstechnik GmbH, Am TÜV 1, 45307 Essen, datenschutz@deutschehospitality.com
H Rewards Loyalty Program, H Rewards Pte. Ltd.: Wodianka privacy legal GmbH, Dockenhudener Straße 12a, 22587 Hamburg, eu-representative@hrewards.com