The travel trade organisation, Abta, says a cyber attack on its website may have affected about 43,000 people.
About 1,000 files accessed may include personal identity information of individuals who have made a complaint about an Abta-registered travel agent.
It says it is contacting those affected by the hack which happened on 27 February and has a dedicated helpline for people with concerns.
It has also alerted the Information Commissioner and the police.
Abta chief executive Mark Tanzer said he would “personally like to apologise for the anxiety and concern” caused to Abta customers and members.
“It is extremely disappointing that our web server, managed for Abta through a third party web developer and hosting company, was compromised and we are taking every step we can to help those affected.
“I will personally be working with the team to look at what we can learn from this situation.”
He said Abta was not aware of any information being shared beyond the infiltrator.
The types of data accessed included:
- email addresses and encrypted passwords of Abta customers and members registered on the website
- contact details of customers of Abta members who have used the website to register a complaint
- data uploaded to support a complaint made about an Abta member since 11 January 2017
- data uploaded by Abta members in support of their membership
Abta said the “vast majority” of the 43,000 people affected were those who had registered with email addresses and encrypted passwords or had filled in an online form with basic contact details.
It said there was “a very low exposure risk to identity theft or online fraud” with this kind of data.
It advised customers and ABTA members registered on the site to change their passwords as a “precautionary measure”.
Abta said those who had uploaded contact details or documentation on the website should actively monitor their bank accounts, social media and email accounts, and “remain vigilant”.
It has also offered people who may be affected a free-of-charge identity theft protection service.