Scworld Massive Data Breach Exposes 5M Hotel Guests' Information via Compromised Platforms
Article Content
- •Nearly 5 million hotel guests' data exposed due to breaches in Chekin and Gastrodat.
- •Over 500 hotel accounts were compromised, allowing for extensive data extraction.
- •Python scripts on the leaking server suggest real-time data exfiltration to Telegram.
A significant data breach has compromised the personal information of nearly 5 million hotel guests due to vulnerabilities in the Spanish automated check-in service Chekin and the Austrian hotel management software Gastrodat. The breach was discovered on March 24, 2026, when a leaking server containing 6.5GB of sensitive data was found. This incident affects over 170 hotels worldwide, with data from approximately 400,000 individual bookings exposed. The leaked information includes guest names, stay dates, reservation IDs, and internal safety flags. Attackers exploited more than 500 compromised hotel and host accounts to infiltrate the booking systems. Python scripts found on the server indicate that data was automatically extracted and potentially forwarded in real-time to Telegram channels. Neither Chekin nor Gastrodat has publicly commented on the incident. The scale of the breach raises concerns about the security of hospitality platforms and the potential for further exploitation of the leaked data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Chekin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…