Daixin ransomware attack took Omni Hotels & Resorts systems offline for a week

Organization
Omni Hotels & Resorts
Exploit
Ransomware
Industry
Hospitality

Omni Hotels & Resorts, which operates roughly 50 properties across the United States, Canada and Mexico, lost the use of its core technology on Friday, March 29, 2024. The chain shut systems down after detecting the intrusion, and the outage took out reservation and check in systems, room key and door lock systems, point of sale payment terminals, the company website and its phone line.

Hotels stayed open and kept accepting guests, but front desk staff had to work manually and reported difficulty creating new reservations, taking card payments and changing existing bookings. BleepingComputer reported that employees were told the IT team was rebuilding affected servers from scratch. Omni confirmed on April 3 that a cyberattack was behind the disruption, and systems were restored across all properties by April 8.

The Daixin Team ransomware group claimed the attack about two weeks later and listed Omni on its leak site. Screenshots the group shared with DataBreaches.net pointed to a database of more than 3.5 million guest records going back to 2017. According to SecurityWeek, Daixin initially demanded $3.5 million and later lowered the figure to $2 million. Omni did not say whether it paid.

In a subsequent notice, Omni said affected information may have included customer names, email addresses, mailing addresses and Select Guest loyalty program details, and that payment card data, other financial information and Social Security numbers were not involved. The company did not disclose how many people were affected.

Sources