Bel Air on Broadbeach is writing to inform you of a recent cyber incident affecting one of our online systems that involved exposure of our guests’ payment card information.
What happened?
We manage guest and reservation-related information on a cloud-based system owned by our third-party supplier. In early May 2026 we were notified that one or more of our user accounts in the system had been compromised.
The supplier and its specialist cybersecurity and legal advisors worked earnestly to investigate the incident. The supplier has now confirmed that the incident led to unauthorised use of our account to access some cardholder information which we collected as part of your previous or current reservation.
What information was affected?
Through this incident, the unknown external party was able to access details of your payment card
In particular:
- the cardholder’s name; and
- the payment card number, CVC and expiry date
- engaging cybersecurity specialists to investigate and contain the cyber incident and its impacts;
- monitoring the dark web for any publication of cardholder details from this incident. Importantly, to date their searches have not identified any publication of other information in connection with this incident;
- requiring all users to change their passwords and re-login to the system; and
- additional steps for improving the overall security of the system and monitoring processes, to effectively identify and prevent any unauthorised access in the future.
- review your card statements to check for any unusual or unknown purchases or transactions;
- if you notice suspicious transactions or other activity involving your payment card or account, promptly contact your bank or card issuer to inform them and ask them to cancel and replace the affected card; and
- if your affected card is cancelled, destroy the physical card.
- consider using a second card with a low credit limit for online transactions. This way, if your credit card details are compromised, this will minimise your risk of financial losses. If you need to cancel your card, you will still be able to continue using your primary credit or debit card;
- be suspicious of any requests for payment card details over email or phone. Any payment we request will be via a secure payment link or through one of our trusted booking platforms (such as Booking.com, Agoda, Qantas Hotels, AirBnB, etc.); and
- not enter your financial information on websites that are not secure or that do not appear legitimate. For example, if your Internet browser says that the site is not secure, that the padlock in the URL is missing, or there are spelling errors or extra characters in the website address (e.g., h0tel(.)com3).
We and our supplier has also partnered with IDCARE, a national identity and cyber support service. They have expert Case Managers who can help address any concerns in relation to personal information risks and any instances where you think your information may have been misused. IDCARE’s services are at no cost to you. This service is available for you to use up until 4 June 2027.
If you’d like us to confirm which specific card was affected, please provide your email address below and we’ll send you that information directly.
CONTACT INFORMATION
Collecting emails who were affected by security breach
Yours sincerely,