ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Thousands of Hotel Guests in Italy Targeted in Major Data Theft, Officials Confirm

A threat actor has reportedly stolen sensitive personal documents belonging to thousands of guests who checked into hotels across Italy, according to the emergency response team at the Agency for Digital Italy.

 

In a recent press release, officials from the Emergency Response Team at the Agency for Digital Italy (CERT-AGID) announced the detection of an illegal sale of identity documents, stolen from hotels operating in Italy, on the dark web.

 

According to the press release, the threat actor, operating under the alias ’mydocs’, posted the stolen material for sale on a well-known underground forum. The data is believed to have been exfiltrated between June and July 2025 through unauthorised access to the systems of three Italian hotel facilities. 

 

The compromised data includes the sensitive personal documents of guests, such as high-resolution scans of passports, identity cards, and other identification documents used during check-in procedures.

 

CERT-AGID has confirmed that the threat actor, mydocs, has started selling stolen identity documents on the dark web, releasing multiple batches allegedly taken from a growing number of Italian hotel facilities. So far, the leaked data includes high-resolution scans of passports, ID cards, and other check-in documents, with claims now totalling over 100,000 stolen records from at least ten hotels. 

 

While the data security incident appears to have taken place in June and July of this year, it is unclear how many years the hotels retain these scans and, therefore, how many customers in total may have been affected. Authorities have warned that additional cases may still come to light.

 

“Given the increasing frequency of these illegal activities, it is increasingly evident how essential it is that the structures that collect and manage identity documents adopt strict measures for the protection and security of information, ensuring not only the correct processing of data, but also the safeguarding of their systems and digital portals from unauthorised access,” CERT-AGID said.

 

Government officials have advised guests who stayed at hotels in Italy to remain vigilant for potential misuse of their personal data.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543