Otelier breach exposes hotel guest reservations for Marriott, Hilton and Hyatt
- Organization
- Otelier
- Exploit
- Credential Compromise
- Industry
- Hospitality Technology
Otelier, a cloud based hotel management platform, was breached in 2024 by attackers who reached its Amazon S3 storage and copied guest reservation records for properties operating under brands including Marriott, Hilton, Hyatt and Wyndham. The breach became public in mid January 2025.
According to CyberInsider, the intruders first logged into Otelier's Atlassian server using an employee's credentials harvested by information stealing malware. From there they read support tickets and internal documentation containing further credentials, which opened access to the company's S3 buckets. The attackers said they held access from July 2024 until a credential rotation cut them off in September, with some activity continuing into October, and claimed to have taken about 7.8 terabytes of data.
The stolen material was described as including guest names, addresses, phone numbers, email addresses, reservation and travel details, nightly reports, shift audits, accounting data and employee correspondence. Partial payment card data appeared in a small number of records.
Troy Hunt loaded the data into Have I Been Pwned on January 18, 2025, recording 436,900 unique email addresses. A further 868,000 machine generated addresses tied to Booking.com and Expedia reservations were left out. Hunt reported a reservations table of roughly 39 million rows and a users table of around 212 million entries, many of them duplicates.
Otelier, which serves more than 10,000 hotels, confirmed the compromise and said it was contacting affected customers. Marriott suspended automated services from the vendor while the investigation continued.