LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › BWH Hotels (Best Western) Discloses 6-Month Reservation System Breach

HIGH severityReportedHow we verify

BWH Hotels (Best Western) Discloses 6-Month Reservation System Breach: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 8, 2026
BWH Hotels (Best Western) Discloses 6-Month Reservation System Breach

Reported May 8, 2026. Approximately tens of thousands people affected.

HIGH
Severity
tens of thousands
People affected
5
Data types exposed
May 8, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

BWH Hotels (Best Western) has disclosed a breach of its reservation system that exposed the names, email addresses, telephone numbers, home addresses, and reservation details of tens of thousands of individuals. The disclosure was made public on May 8, 2026; affected customers should check their accounts and monitor for suspicious activity.

Severity & verification
HIGH severityReported
Contact / identity PII exposed.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
tens of thousands accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

BWH Hotels notified tens of thousands of guests that unauthorized parties maintained access to its reservation web application for roughly six months. The company confirmed the access and began issuing notifications in early May 2026. Contact information and reservation details may have been exposed, while payment data remained outside the affected system.

What happened

BWH Hotels, the parent company of Best Western, WorldHotels and SureStays, stated that intruders held access to its reservation web application between October 2025 and April 2026. The company detected the activity, confirmed the unauthorized presence, and began notifying affected guests on or around May 8, 2026. The disclosure indicated that the incident involved tens of thousands of individuals. No further technical details on the initial point of entry or the precise volume of records have been released publicly.

How a breach like this happens

Web applications that handle reservations often remain accessible over the internet and process structured data such as names, addresses and booking records. Attackers can obtain prolonged access when credentials are compromised, software vulnerabilities remain unpatched, or session controls are insufficient. Once inside, they may move laterally within the application or its supporting infrastructure while avoiding detection for weeks or months. Organizations typically discover such activity through log analysis, anomaly detection, or external reports rather than real-time alerts.

BWH Hotels and its sector

BWH Hotels operates multiple lodging brands and maintains reservation systems that collect personal and booking information from guests worldwide. Hotel groups routinely store contact details and itinerary data to manage bookings, loyalty programs and customer service. A prolonged compromise of such a system is consequential because the data supports repeated interactions with customers and can be reused across different services or sold in bulk.

What data was at risk

The company reported that names, email addresses, telephone numbers, home addresses and reservation details may have been exposed. It stated that payment data was neither stored nor accessed in the affected reservation web application. No additional categories of information have been confirmed or ruled out in public statements, so the complete scope remains limited to the fields explicitly named.

The real-world impact

Exposed names, addresses and contact details can be used for targeted phishing or unwanted marketing. Reservation details may reveal travel patterns that, when combined with other available information, increase the chance of account takeover attempts on loyalty programs or related services. For the organization, the incident adds notification costs, potential regulatory scrutiny and the need to review access controls on customer-facing systems. Individuals face these risks incrementally rather than through immediate large-scale fraud in most cases.

If your data was in this claimed breach

Review any notification letter for instructions on monitoring accounts and consider changing passwords for the affected loyalty or reservation profiles. Enable multi-factor authentication where available and watch for unusual emails or calls that reference the booking information. Individuals can also run a free exposure scan of their email address against known breach datasets to determine whether their information appears in other incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyBWH Hotels security record
71/100
DoxxScan™ · Moderate doxx risk
C+ 71Fair record

1 reported incident on record.

See BWH Hotels’s full breach history →

More recent breaches

Aflac Japan Discloses Breach Impacting 4.38M CustomersJune 30, 2026AssuranceAmerica Breach Exposes 6.9M Driver's LicensesJuly 8, 2026SBI Software Hit by Genesis Data LeakJuly 6, 2026Kodak Confirms Data Breach Claimed by ShinyHuntersJune 17, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the BWH Hotels (Best Western) Discloses 6-Month Reservation System Breach →

Source: Cybernews

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram