Data Breaches

BWH Hotels Says Hackers Had Access to Reservation Data for 6 Months

Threat actors obtained names and contact information for an unspecified number of BWH Hotels guests.

Best Western

Hospitality group BWH Hotels is informing some guests that hackers had access to reservation data for more than six months. 

BWH Hotels operates more than 4,000 hotels worldwide, including brands such as WorldHotels, Best Western Hotels & Resorts, and Sure Hotels.

Emails sent to customers affected by the data breach reveal that the intrusion was discovered on April 22, and an investigation showed that threat actors had access since October 14, 2025.

The company said the attackers gained access to a web application housing some guest reservation data, including names, email addresses, phone numbers, and reservation details. 

“Importantly, payment and other financial information was not stored in the affected system and therefore was not accessed,” BWH Hotels stated.

It’s unclear how many individuals were affected by the incident. 

Advertisement. Scroll to continue reading.

The company took the compromised application offline after discovering the intrusion and launched an investigation with the aid of external security experts. 

The hotel group seems concerned that the attackers may leverage the stolen data for scams and phishing.

No known cybercrime group appears to have taken credit for the attack on BWH Hotels.

Related: Booking.com Says Hackers Accessed User Information

Related: Nightclub Giant RCI Hospitality Reports Data Breach

Related: Sophisticated ClickFix Campaign Targeting Hospitality Sector

Related Content

Data Breaches

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

Data Breaches

The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.

Artificial Intelligence

A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.

Data Breaches

Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.

Data Breaches

The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. 

Data Breaches

The attackers used a compromised BigCommerce application key held by Ribon to access customer data.

Data Breaches

The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.

Data Breaches

Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version