Menu
Browse

Cyber Incident Victim: Whitbread

Date:

Jul 2018

Location:

United Kingdom

Summary

Whitbread experienced a data breach impacting its online recruitment system, managed by third-party provider PageUp, compromising applicant and employee data submitted to brands including Premier Inn and UK-based Costa Coffee outlets. Exposed information included contact, biographical, and employment details, with potential identity theft risks if combined with other data. The company suspended PageUp's services upon discovery, prevented further data uploads, and advised affected individuals to change reused passwords, though no fraudulent activity was confirmed. Whitbread acknowledged the incident with an apology, emphasizing careful partner selection and data security measures while confirming minimal operational presence in Ireland beyond a single Premier Inn location.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

In July 2018, Whitbread PLC experienced a data breach affecting its online recruitment system managed by third-party provider PageUp. The incident impacted recruitment data for several Whitbread brands, including Premier Inn and UK-based Costa Coffee outlets. PageUp stored applicant information submitted to Whitbread, potentially exposing personal details of prospective and current employees. On July 2, 2018, Whitbread notified affected individuals via email, stating there was a possibility that submitted recruitment data "may have been accessed" and could be exploited for identity theft when combined with other information. The compromised data categories included contact details, biographical information, and employment history. Whitbread emphasized that PageUp had not detected any fraudulent activity stemming from the breach at the time of disclosure.

Cyber Incident Image

Whitbread suspended its use of PageUp's services immediately upon discovering the incident and blocked current applicants from uploading additional data to the system. The breach primarily affected UK operations, with Whitbread confirming its sole Irish presence as a Premier Inn at Dublin Airport and Northern Irish operations encompassing seven Premier Inns and approximately 20 Costa Coffee outlets. The company advised impacted individuals to change passwords if they reused credentials across multiple online services. In communications, Whitbread apologized for the incident while underscoring their careful partner selection processes and commitment to data security. No evidence suggested operational disruptions to Whitbread's hospitality or retail services beyond the recruitment system suspension.

Sources
Sources available to members
1 source