Supply chain
β Supply Chain
Wyndham Third-Party Breach (January 2025)
Primary Source βIncident Details
Otelier data breach exposes info, hotel reservations of millions. Hotel management platform Otelier suffered a data breach after threat actors breached its Amazon S3 cloud storage to steal millions of guests’ personal information and reservations for well-known hotel brands like Marriott, Hilton, and Hyatt. The breach first allegedly occurred in July 2024, with continued access through October, with the threat actors claiming to have stolen amost eight terabytes of data from Otelier’s Amazon AWS S3 buckets. In a statement to BleepingComputer, Otelier confirmed the compromise and said it is communicating with impacted customers. Third-party company: Otelier.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Otelier
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-01-01 Breach occurred
- 2025-01-17 Publicly disclosed