Dutch-Themed Amusement Park in Japan Reports Massive Data Breach Affecting 1.5 Million
On December 15, 2025, Huis Ten Bosch—a Dutch-themed amusement park in Nagasaki, Japan—disclosed that a cybersecurity breach on August 29 may have exposed the personal data of over 1.5 million individuals. The affected parties include customers, current and former employees, and business partners.
The company is currently reviewing its cybersecurity and business-continuity protocols in response to the incident. While details remain limited, the breach highlights growing risks to large-scale entertainment and hospitality operations. Officials have not yet confirmed the full scope of compromised data or the attack’s origin. The incident underscores the increasing regulatory scrutiny on data protection in Japan and globally.
H.I.S. Travel Nederland B.V. cybersecurity rating report: https://www.rankiteo.com/company/h.i.s.-travel-nederland-b.v.
"id": "H.I1765771448",
"linkid": "h.i.s.-travel-nederland-b.v.",
"type": "Breach",
"date": "8/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1.5 million+ (including '
'customers, current/former '
'employees, and business '
'partners)',
'industry': 'Entertainment/Leisure',
'location': 'Nagasaki, Japan',
'name': 'Huis Ten Bosch',
'type': 'Amusement Park'}],
'data_breach': {'number_of_records_exposed': '1.5 million+',
'type_of_data_compromised': 'Personal data'},
'date_detected': '2025-08-29',
'date_publicly_disclosed': '2025-12-15',
'description': 'Huis Ten Bosch, the Dutch-themed amusement park in Nagasaki, '
'Japan, reported a data breach on August 29 that may have led '
'to data leaks impacting more than 1.5 million people, '
'including customers, current and former employees, and '
'business partners.',
'impact': {'data_compromised': 'Personal data of over 1.5 million '
'individuals'},
'investigation_status': 'Ongoing (review of cybersecurity and '
'business-continuity procedures)',
'post_incident_analysis': {'corrective_actions': 'Review of cybersecurity and '
'business-continuity '
'procedures'},
'references': [{'date_accessed': '2025-12-15', 'source': 'MLex'}],
'response': {'communication_strategy': 'Official statement released on '
'December 15, 2025'},
'title': 'Huis Ten Bosch Data Breach',
'type': 'Data Breach'}