BWH Hotels—parent of Best Western, WorldHotels, and Sure Hotels—told guests in May 2026 that someone had been inside a reservation web application since October 14, 2025. The intrusion was spotted April 22, 2026. Names, emails, phone numbers, home addresses, reservation numbers, stay dates, and special requests were in scope. Payment cards were not stored in that system.
What happened
CTO Bill Ryan's notification letter, summarized by The Register, said BWH took the application offline, revoked unauthorized access, and brought in outside incident-response help. No public victim count has been published.
Why UK guests are getting a second warning
By June 2026, UK outlets including the Liverpool Echo and Daily Express were telling summer travellers to treat unexpected hotel messages as suspect. The risk is not missing card data—it is context. If a scammer already knows your hotel, dates, and booking reference, a fake "confirm your stay" or "payment failed" text reads like customer service, not spam.
What was exposed
Contact fields plus reservation metadata, including special requests that can hint at accessibility needs, family arrangements, or travel reasons. BWH's own guidance warns against replying to unsolicited email, SMS, or WhatsApp messages that ask for payment, codes, logins, or verification—even when they name a real property.
What you should do
- If you booked Best Western, WorldHotels, or Sure Hotels between October 2025 and April 2026, slow down on any surprise booking message.
- Open the official hotel site or your original confirmation—do not click links or call numbers sent in suspicious texts.
- Treat pre-check-in urgency as a red flag; verify through BWH customer service if unsure.
- Report payment details entered into a scam page to your bank immediately.
Canonical record: BWH Hotels 2026 reservation incident on BreachHistory.
Sources: The Register, Liverpool Echo, Daily Express