Supply chain β›“ Supply Chain

Wyndham Third-Party Breach (January 2025)

πŸ“… 2025-01-01 🏒 Otelier
Primary Source β†—

Incident Details

Otelier data breach exposes info, hotel reservations of millions. Hotel management platform Otelier suffered a data breach after threat actors breached its Amazon S3 cloud storage to steal millions of guests’ personal information and reservations for well-known hotel brands like Marriott, Hilton, and Hyatt. The breach first allegedly occurred in July 2024, with continued access through October, with the threat actors claiming to have stolen amost eight terabytes of data from Otelier’s Amazon AWS S3 buckets. In a statement to BleepingComputer, Otelier confirmed the compromise and said it is communicating with impacted customers. Third-party company: Otelier.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Otelier
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-01-01 Breach occurred
  2. 2025-01-17 Publicly disclosed