BWH Hotels confirmed a cyberattack after detecting unauthorized access on April 22 that exposed customer reservation information stored in a web application. The compromised data included guests' names, email addresses, phone numbers, postal addresses, reservation numbers, stay dates, and special requests, with records generated between October 14, 2025 and April 22, 2026 potentially affected. The company said payment card and bank account information were not impacted.
BWH Hotels said it took the affected application offline, revoked the unauthorized access, and brought in external cybersecurity experts to investigate and strengthen defenses. The company also warned customers to watch for phishing and other suspicious communications—including emails, texts, WhatsApp messages, or phone calls—that reference hotel reservations or stays and could use the stolen personal details to appear legitimate.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
In May 2026, BWH Hotels publicly confirmed the cyberattack and warned customers that reservation and personal information may have been exposed. The disclosure stated that the affected data set covered records generated between October 14, 2025, and April 22, 2026.
Following detection of the intrusion, BWH Hotels took the affected application offline, revoked unauthorized access, and engaged external cybersecurity experts to investigate and strengthen safeguards. The company also began advising customers to watch for phishing and other suspicious communications referencing hotel reservations.
On April 22, 2026, BWH Hotels detected unauthorized access affecting a web application that stored guest reservation information. The incident exposed customer data including names, email addresses, phone numbers, postal addresses, reservation details, stay dates, and special requests, but not payment card or bank information.
BWH Hotels said the customer reservation data later exposed in the breach was generated starting on October 14, 2025. This marks the beginning of the known data range stored in the compromised web application.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcescworld.com
Open sourcetechradar.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.