Millions of hotel users see personal info checked out in huge data leak

Suitcase next to a bed in a hotel
(Image credit: Getty Images)

  • CyberNews researchers have discovered a huge data leak
  • The dataset contained the information of over 24 million customersIt likely belonged to hotel chain Honotel

A leaked dataset which contained over 24 million hotel records has been discovered by CyberNews researchers, which included names, emails, phone numbers, and detailed stay information like arrival time, number of guests, and price paid.

There are strong indications that the dataset belongs to Honotel Group, a French hospitality investment and management firm.

The data specifically mentions ‘SITE HONOTEL’, researchers confirmed, as well as booking platforms such as Booking.com - suggesting the leaked database might be part of Honotel’s booking management system.

Guests at risk

Researchers discovered the suspected Honotel leak on October 4, 2024, and the leak was closed by October 7 2024, so the organization at least acted quickly once the disclosure notice had been sent.

It’s not clear how long the data was available, or if threat actors discovered or stole anything, but the information was discovered on an unprotected Elasticsearch server and Kibana interface.

This puts both the customer and the company at risk. For the customer, the risk when Personally Identifiable Information (PII) is compromised is the risk of fraud and identity theft, as malicious actors can use the data to take out loans, bank accounts, or even to develop social engineering attacks against the victims.

For the company, much like the FTC fines, European firms face GDPR regulations which could see penalties of up to 4% of a company’s global annual revenue if best security practices are not put in place to protect PII.

This comes not long after major incidents led the FTC to order the Marriott and Starwood hotel chains to implement more robust security measures after 344 million customers were left exposed in a massive data breach. Marriott systems were exposed for up to four years, earning the firm a $52 million penalty from the FTC in 2024.

You might also like

Ellen Jennings-Trace
Staff Writer

Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Ransomware
Millions of hotel guest reservations leaked in Otelier data breach
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Security padlock and circuit board to protect data
A major US TV broadcaster leaked over a million sensitive files online
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras