Massive Data Breach Exposes 5M Hotel Guests' Information via Compromised Platforms

Massive Data Breach Exposes 5M Hotel Guests' Information via Compromised Platforms

First seen 17 Apr 2026, 02:00 UTC CybernewsScworld 85% similarity 64.5

Article Content

Browse articles
ThreatCluster

A significant data breach has compromised the personal information of nearly 5 million hotel guests due to vulnerabilities in the Spanish automated check-in service Chekin and the Austrian hotel management software Gastrodat. The breach was discovered on March 24, 2026, when a leaking server containing 6.5GB of sensitive data was found. This incident affects over 170 hotels worldwide, with data from approximately 400,000 individual bookings exposed. The leaked information includes guest names, stay dates, reservation IDs, and internal safety flags. Attackers exploited more than 500 compromised hotel and host accounts to infiltrate the booking systems. Python scripts found on the server indicate that data was automatically extracted and potentially forwarded in real-time to Telegram channels. Neither Chekin nor Gastrodat has publicly commented on the incident. The scale of the breach raises concerns about the security of hospitality platforms and the potential for further exploitation of the leaked data.

Key Points: • Nearly 5 million hotel guests' data exposed due to breaches in Chekin and Gastrodat. • Over 500 hotel accounts were compromised, allowing for extensive data extraction. • Python scripts on the leaking server suggest real-time data exfiltration to Telegram.

ThreatCluster AI

Timeline

2026-03-24
Leaking server discovered containing 6.5GB of data.
2026-04-15
Cybernews publishes findings on the data breach.
2026-04-16
Scworld reports on the breach and its implications.

Community

Browse all →