Important Information about Data Breach

We are deeply sorry to inform you that a data breach occurred on our hotel system provider’s platform on Sunday, 4.1.2026, affecting our accommodation guests with an arrival date on 4.1.2026 or after. We received the first information about a potential data breach on 6.1.2026 evening, and we immediately started taking action and investigating the situation. According to the information we gathered during our investigation, an external party successfully bypassed two-factor authentication by creating a fraudulent website, thereby gaining unauthorized access to our accommodation booking data, which is listed below.

We have already got information about phishing attempts on text messages (SMS) and WhatsApp. Don’t click any links or add your payment details!

We strongly advise you to ignore any suspicious messages and emails, especially those that:

  • Contain suspicious links or QR codes
  • Urge to act quickly or within a specific time frame
  • Request sensitive information or payment details.

If you have already clicked on a fraudulent link or added your payment details, we advise you to contact your bank immediately. After that, please report the phishing/scam to the police.

We have taken immediate actions to enhance our security on all critical platforms. We feel it is crucial to inform all affected guests as soon as possible about the data breach to protect our guests from potential phishing attempts. The incident will be reported to the authorities, including the Data Protection Ombudsman’s office, the Finnish Transport and Communications Agency’s National Cyber Security Centre (Traficom), and the police.

We are currently personally informing all affected guests. We are also continuing to enhance security procedures in collaboration with cybersecurity experts and authorities to prevent such events in the future.

The affected data includes the following information about bookings with arrival dates after 4.1.2026 and booked before 5.1.2026:

  • Full name
  • Phone number
  • Email address
  • Home address
  • Nationality
  • Payment card type, expiration date, and last four digits (NOT full payment details)
  • Reservation details (booking reference, cost, room type, arrival/departure dates)
  • Travel agency details (if applicable)

We deeply regret any distress or inconvenience this situation may cause. Our guests’ privacy and security remain our highest priorities, and we are fully committed to enhancing our cybersecurity in daily operations by reviewing and updating our systems, providing further training to our staff, and emphasizing the importance of cybersecurity.

If you receive any suspicious messages, we strongly advise against opening them, scanning any QR codes, or clicking on links. In such cases, we kindly request that you notify our team immediately via email at sales@apukkaresort.fi or by phone at +358 29 370 0269.

If you have any concerns or have received suspicious messages, please do not hesitate to reach out. Our customer service team is available daily at 9 AM to 9 PM (Finnish time).

 

Best regards,
Harri Mällinen, CEO & The Executive Team
Apukka Resort Ltd.


Please be aware of phishing attempts! If you receive any suspicious messages, we strongly advise against opening them, scanning any QR codes, or clicking on links.

To protect yourself, please disregard any messages that:

  • Contain QR codes or suspicious links.
  • Pressure you to act urgently or within a limited timeframe.
  • Request sensitive information or payment details.

Questions and Answers

We are updating this Q&A regarding the data breach

Unfortunately, your data has leaked if your arrival date to Apukka Resort is after 4.1.2026 and you have booked before 5.1.2026.

We recommend staying alert to suspicious messages or emails and avoiding clicking on unfamiliar links or QR codes. If you receive any messages that seem unusual, please notify us immediately.

Unfortunately, your data has leaked if your arrival date to Apukka Resort is after 4.1.2026  and you have booked before 5.1.2026.

We recommend staying alert to suspicious messages or emails and avoiding clicking on unfamiliar links or QR codes. If you receive any messages that seem unusual, please notify us immediately.

Unfortunately, your data has leaked if your arrival date to Apukka Resort is after 4.1.2026 and you have booked before 5.1.2026, but it’s limited to your name, travel dates, and travel agency/tour operator information. Your contact information or other personal information hasn’t leaked.

We recommend staying alert to suspicious messages or emails and avoiding clicking on unfamiliar links or QR codes. If you receive any messages that seem unusual, please notify us immediately.

We can confirm that emails from sales@apukkaresort.fi are safe to open, as this is our official contact address. However, as a security measure, please ensure the sender’s email address is spelled exactly as mentioned above. Cybercriminals may sometimes use very similar-looking addresses to impersonate legitimate senders.

Our email regarding the online check-in contains a QR code, but you don’t need to scan it. We recommend completing the online check-in for a smoother arrival experience, but please note that it is optional and not mandatory. If you prefer, you can also check in at the reception upon arrival.

We take every necessary measure to secure our systems and protect our guests’ data with the assistance of system providers and Finnish authorities.

We have always been working in accordance with GDPR compliance, relevant laws, and the advice of authorities. Only over the past year, we have implemented several enhancements to data security, as outlined below.

• A security audit covering both physical premises and digital environments was conducted by the third-party company.
• Reviewed and updated data protection and information security policies.
• Implemented structured user account and access control policies.
• Deployed a modern, centrally managed security solution to protect company devices and systems.
• Implemented regular data backups to protect critical information.
• Implemented a dedicated learning management system for employee training.
• Conducted mandatory employee training at the start of the season.
• Worked in cooperation with a dedicated IT service provider.
• Treated data security as an ongoing and evolving process.

Your booking with us remains fully confirmed, and your reservation details are secure. There is no impact on your stay, and we look forward to welcoming you as planned. If you need any adjustments or have further questions about your booking, our team is here to assist you.

The only data leaked regarding your credit card were the last four digits, the expiry date, and the type of card.

Therefore, fraudulent transactions related to this incident should not be possible. However, as a precaution, we recommend contacting your bank to review any suspicious activity and ensure your financial security.