Security notice — fraudulent messages impersonating our hotel

Published 20 July 2026

Our reservation software provider, Prestige Software, has informed us that an attacker accessed its systems between 6 and 14 July 2026 and copied booking information, which may include guest names, phone numbers, booking references, stay dates and booking values. Payment card details and passport/ID details were not involved — they are not stored in that system.

Criminals are sending WhatsApp messages and emails pretending to be The Embassy Valletta Hotel, asking guests to confirm card details or make a payment to “secure” their booking. These messages are not from us.

Your reservation is confirmed and requires no action. We will never ask you for card details or payment through a link in a WhatsApp message, SMS or email. If you receive a suspicious message, do not reply or click anything — contact us only through this website or on [+356 2016 9000]. If you have already shared card details, contact your bank immediately.

We have reported this incident to the Information and Data Protection Commissioner (IDPC) and to the Malta Police, and we are contacting affected guests directly by email. We are holding our provider to account and reviewing our relationship with them.