Cybercrime

Cyberattack Causes Disruptions at Omni Hotels

Omni Hotels & Resorts tells customers that recent disruptions have been caused by a cyberattack that forced it to shut down systems.

Omni Hotels & Resorts tells customers that recent disruptions have been caused by a cyberattack that forced it to shut down systems.

Omni Hotels & Resorts has told customers that the recent disruptions have been caused by a cyberattack that forced it to shut down some systems.

The Texas-based Omni Hotels & Resorts runs 50 upscale hotels and resorts across North America, offering more than 23,000 rooms. According to its website, it has roughly 14,000 employees. 

In a notice on its website, the company said it started responding to a cyberattack on March 29. 

“Upon learning of this issue, Omni immediately took steps to shut down its systems to protect and contain its data,” the hotel chain said.

“We are currently working to determine the scope of the event, including impact to any data or information maintained on Omni systems. Our investigation into the incident remains ongoing and we are working with external specialists in this process,” it added.

The hotel said most of the systems that were taken offline in response to the attack have been brought back online. Its website is currently working and reservations can be made online.

Advertisement. Scroll to continue reading.

Customers who had been staying at Omni hotels when the incident started reported check-ins being done on paper, room keys not working, and being unable to pay with credit cards. 

The disruption may be the result of a ransomware attack, but no known cybercrime group appears to have taken credit for it.

SecurityWeek has reached out to Omni Hotels to find out whether this was a ransomware attack, but the company referred us to the notice on its website.

Related: Hotel Self Check-In Kiosks Exposed Room Access Codes

Related: Information of European Hotel Chain’s Customers Found on Unprotected Server

Related: MGM Resorts Says Ransomware Hack Cost $110 Million

Related Content

ICS/OT

The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. 

ICS/OT

The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.

Incident Response

The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.

Cybercrime

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

ICS/OT

The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks.

Cybercrime

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.

Cybercrime

The company disconnected its systems on July 13 and is starting to gradually restore operations.

Data Breaches

Threat actors obtained names and contact information for an unspecified number of BWH Hotels guests.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version