
We're for
new adventures
Important information about a recent data security incident
Last updated: 16 September 2026
At NRMA Parks & Resorts, we take the privacy and security of our guests’ personal information seriously.
We are writing to let you know about a recent data security incident involving Amadeus iHotelier, a third-party reservation platform used to support bookings at some of our Tasmanian properties, including Freycinet Lodge, Cradle Mountain Hotel and Strahan Village.
We understand that news of a security incident can be concerning, and we are sorry this has occurred. We want to be transparent about what we know, what information may have been involved, and the steps we are taking in response.
What happened?
Amadeus advised us that an unauthorised third party gained access to limited guest contact information associated with certain reservations held within its iHotelier platform. Amadeus has advised that it has identified and closed the access route used in the incident and that there is no ongoing unauthorised access.
We are continuing to work closely with Amadeus and our security and privacy teams as the investigation is completed.
What information may have been involved?
Based on the information provided to us by Amadeus, the information involved may include:
· Name
· Email address
· Telephone number
Importantly, Amadeus has advised that the incident did not involve:
· Payment card information
· Financial information
· Passwords
· Passport information
Your reservation remains valid and there is no impact to your upcoming stay because of this incident.
What are we doing?
As soon as we were notified, we began working with Amadeus and our technology, cyber security and privacy teams to understand what had occurred and determine which guests may have been affected.
We have taken a few steps, including:
· Reviewing the information and findings provided by Amadeus
· Identifying and contacting guests who may have been affected
· Confirming with Amadeus that the access route used in the incident has been closed
· Briefing our property and guest service teams
· Establishing dedicated support and escalation processes for guest enquiries
· Continuing to work with Amadeus as its investigation is completed
We are also reviewing the incident and any additional measures that may be appropriate to further protect our guests’ information.
What should I do?
While the information involved is limited, we encourage guests to be particularly alert to unexpected or unusual communications about their accommodation booking.
Knowing details associated with a genuine booking can make a fraudulent email, text message or phone call appear more convincing.
As a precaution, we recommend that you:
· Be cautious of unexpected emails, text messages, WhatsApp messages or phone calls relating to your booking
· Do not click on links or open attachments in communications you are unsure about
· Never provide payment card details, passwords or one-time security codes in response to an unexpected request
· Be particularly cautious of unexpected requests to make or change a payment
· Contact the property directly using the details on our official website if you are unsure whether a communication is genuine
Frequently asked questions
Was my booking affected?
Your reservation remains valid and your upcoming stay is not affected.
The incident relates to limited contact information associated with certain reservations held within the Amadeus iHotelier platform. If we have identified your information as potentially affected, we will contact you directly.
Has NRMA Parks & Resorts been hacked?
The unauthorised access occurred within Amadeus iHotelier, a third-party reservation platform, rather than NRMA Parks & Resorts' own systems.
However, because the platform is used to support bookings for some of our properties, we take this incident seriously and are working closely with Amadeus and our own cyber security and privacy teams to respond.
Was my payment information accessed?
Based on the information currently provided to us by Amadeus, payment card and financial information were not involved in this incident. Amadeus has also advised that passwords and passport information were not involved.
How will I know if I am affected?
We are contacting guests identified as potentially affected based on the information provided to us by Amadeus. Our review is continuing. If we identify additional guests whose information may have been affected, we will contact them directly.
What should I do if I receive a suspicious message about my booking?
Do not click on links, make a payment or provide personal or security information if you are unsure whether a communication is genuine. Instead, contact the property directly using the contact details on your booking confirmation or our official website.
Do I need to cancel my card or change my passwords?
Based on the information currently available to us, payment card details and passwords were not involved, so there is no indication that you need to cancel your card or change your passwords because of this incident. We do, however, recommend remaining alert to suspicious communications that may refer to your booking.
We’re here to help
We understand you may have questions or concerns and have established a dedicated team to assist and can be contacted on [email protected].
We sincerely apologise for any concern or inconvenience this incident may cause. Protecting our guests’ information is important to us, and we will continue to work with Amadeus and our security and privacy teams to understand the incident fully and take any further action required.
We will update this page if there are any material new information guests need to know.