BWH Hotels
Incident posture
Linked entities
- Victim
- BWH Hotels
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
BWH Hotels disclosed that attackers gained access to a web application containing guest reservation data and remained inside the system for more than six months before the intrusion was detected. The compromised data included names, email addresses, phone numbers and reservation details, while payment information was not stored in the affected application and therefore was not exposed. After discovery, the company took the application offline and launched an investigation with external security experts, noting concern that the stolen information could be used for scams and phishing attempts. No cybercrime group has claimed responsibility for the breach, which affects the chain’s more than 4,000 properties worldwide, including brands such as WorldHotels, Best Western Hotels & Resorts and Sure Hotels.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
BWH Hotels operates more than 4,000 hotels worldwide, including the brands WorldHotels, Best Western Hotels & Resorts, and Sure Hotels. On April 22, 2025, the company sent emails to affected customers stating that an intrusion had been discovered. The investigation revealed that threat actors had maintained access to a web application containing guest reservation data since October 14, 2025. The accessed data included names, email addresses, phone numbers, and reservation details, while payment and other financial information was not stored in the affected system and therefore was not accessed.
After discovering the intrusion, BWH Hotels took the compromised web application offline to prevent further access. The company launched an investigation with the assistance of external security experts to determine the scope and origin of the breach. The exact number of individuals whose data was exposed has not been disclosed, leaving the scale of the incident uncertain. BWH Hotels expressed concern that the attackers could use the stolen personal information for scams and phishing attempts.
No known cybercrime group has claimed responsibility for the attack on BWH Hotels. The incident adds to a series of reported data breaches affecting the hospitality sector, including similar notifications from Booking.com and RCI Hospitality. The company has not provided further details on any regulatory notifications, legal actions, or additional consequences resulting from the breach.
Sources
Sources available to members: 1 source.