The company said in a statement that the breach involved unauthorised access to some corporate email accounts and its customer service system.
Firm representatives stressed that the issue affects only a small number of users, but urged people to remain vigilant.
Security experts are analysing what happened, it added.
The data potentially included email addresses, names, phone numbers, addresses, dates of birth and passport details.
Wakacje.pl said its payment systems and current bookings were not affected, and that the stolen data could not be used to log in to customer accounts on its website or app.
It warned users to be alert to messages asking for payments or changes to booking details, and to calls from unknown numbers.
Attackers could use the data to trick people into making payments while posing as the company, it said.
The firm advised affected customers to restrict their PESEL national ID number through the mObywatel app or the gov.pl website, and to consider doing the same with their passports.
It said it had informed the cybersecurity incident response team at the state research institute NASK and Poland's Personal Data Protection Office, and would report the case to law enforcement.
(ał)
Source: PAP