Protect yourself after a hotel or travel-data breach
Respond to itinerary, contact and passport exposure without conflating them.

Identify which booking data was involved
A reservation record can contain contact details, stay dates or identity-document information. Check the notice for the fields attributed to you. A past itinerary is not a live location feed.
Verify changes through the provider
Open the hotel or airline’s known app or website to check a refund, cancellation or payment request. A caller knowing a real booking reference still needs independent verification.
Handle document concerns separately
If a passport number or image was involved, ask the issuing authority for guidance suited to your country and circumstances. Avoid declaring a physical passport lost when the issue is only a leaked number; get the correct instructions first.
Reduce unnecessary public context
Review publicly shared itineraries and old booking screenshots. Limit extra information in support messages to what is needed for the request. If a public listing needs removal, retain the URL and use its published process; that does not erase historical breach copies.
