Someone Used AI to Hack Four Hotel Booking Platforms

Someone just used AI to break into four hotel booking platforms. Here's why the breach isn't the scary part — and what GMs need to do this week.

Share
Someone Used AI to Hack Four Hotel Booking Platforms

Your guest's confirmation number just became the most convincing phishing bait in hospitality — here's what to do about it this week.

Not a nation-state. Not an elite hacking crew. One guy, with Claude and an automated pen-testing tool, who got in by framing his queries as a legitimate security audit. That's the sophistication level now. In June, Cybernews disclosed the breach — roughly 2.1 million guest records pulled from booking and property-management platforms. Names, emails, reservation dates, payment details.

That's not the part that should worry you most, though. It's what happens after.

Because stolen reservation data doesn't just sit in a database somewhere. It becomes ammunition. Someone contacts your guest, references their real confirmation number, their real check-in date, your hotel's real name — and your guest believes them. Why wouldn't they? Everything checks out. That's the entire trick. Phishing used to work because people were careless. Now it works because the information is true.

This isn't isolated. BWH Hotels — Best Western's parent company — disclosed in May that attackers had access to guest reservation data for six months before anyone noticed. Separately, compromised credentials at two hospitality platforms exposed data tied to over 5 million guests. This is happening across the industry, right now, at real scale.

And I'd bet most GMs reading this have never had one specific conversation with their front desk or reservations team: what "verified" actually means anymore.

We train staff to spot bad grammar, urgency, obvious red flags. Nobody trains them to be suspicious of accurate information. That's the gap.

I built HotelComply because I lived on the other side of this problem. I ran a property and went looking for a compliance resource built by someone who'd actually stood at a front desk — not a law firm, not a vendor selling fear to a corporate office three states away from the guest standing at check-in. There wasn't one. So I built it.

To be clear about what that means here: HotelComply doesn't stop this kind of attack. No compliance service does. What it does is make sure that when something like this happens — and it is happening — you're not the property that finds out three vendors deep that nobody ever mapped who has access to your guest data.

One things to do this week, not next quarter:

  1. I'm not going to give you a five-step framework. I'm going to give you one conversation to have this week. Walk up to your front desk. Ask them: "If someone calls and knows a guest's confirmation number, are they legit?" If the answer is yes — even a little bit — you have a training gap. Then walk into your back office and ask who has access to your PMS data. If you get a shrug, that's your second problem.

You can't out-engineer every attacker on the planet. Nobody can. But you can make sure you're not the operator who's still reconstructing what happened after the fact, instead of already knowing.

Read more