CSIDB logo
Incident

BWH Hotels

Incident posture

Attack window
Oct 2025
Location
-
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 18:00

Linked entities

Victim
BWH Hotels
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2025
Discovered
Apr 2025
Disclosed
Apr 2025
Resolved
Pending

Summary

BWH Hotels disclosed that attackers gained access to a web application containing guest reservation data and remained inside the system for more than six months before the intrusion was detected. The compromised data included names, email addresses, phone numbers and reservation details, while payment information was not stored in the affected application and therefore was not exposed. After discovery, the company took the application offline and launched an investigation with external security experts, noting concern that the stolen information could be used for scams and phishing attempts. No cybercrime group has claimed responsibility for the breach, which affects the chain’s more than 4,000 properties worldwide, including brands such as WorldHotels, Best Western Hotels & Resorts and Sure Hotels.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

BWH Hotels operates more than 4,000 hotels worldwide, including the brands WorldHotels, Best Western Hotels & Resorts, and Sure Hotels. On April 22, 2025, the company sent emails to affected customers stating that an intrusion had been discovered. The investigation revealed that threat actors had maintained access to a web application containing guest reservation data since October 14, 2025. The accessed data included names, email addresses, phone numbers, and reservation details, while payment and other financial information was not stored in the affected system and therefore was not accessed.

After discovering the intrusion, BWH Hotels took the compromised web application offline to prevent further access. The company launched an investigation with the assistance of external security experts to determine the scope and origin of the breach. The exact number of individuals whose data was exposed has not been disclosed, leaving the scale of the incident uncertain. BWH Hotels expressed concern that the attackers could use the stolen personal information for scams and phishing attempts.

No known cybercrime group has claimed responsibility for the attack on BWH Hotels. The incident adds to a series of reported data breaches affecting the hospitality sector, including similar notifications from Booking.com and RCI Hospitality. The company has not provided further details on any regulatory notifications, legal actions, or additional consequences resulting from the breach.

Sources

Sources available to members: 1 source.

CSIDB