People search Wyndham Hotels & Resorts data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 5 Wyndham Hotels & Resorts-linked incidents, with headline counts up to 600K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Wyndham Hotels & Resorts breach history matters
Wyndham Hotels & Resorts operates in Other (United States). Across indexed rows, recurring themes include credential theft and social engineering. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2014 — — Wyndham Hotels & Resorts: name, address, ssn, financial account info Location…
Cataloged incident. name, address, ssn, financial account info Location of breached information: Desktop Computer Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 1 affected records in this row. See the wyndham2014 and canonical BreachHistory entry.
2013 — — Wyndham Hotels & Resorts: The Orlando Police Department notified Wyndham…
Cataloged incident. The Orlando Police Department notified Wyndham Vacation Ownership that a Wyndham employee had been arrested for participating in fraudulent credit card purchases. The dishonest employee was fired the next day and may have obtained customer credit card numbers. Wyndham learned of the issue on January 18. Exposed categories include Personal information. No attested victim count is published for this row yet. See the wyndham2013 and canonical BreachHistory entry.
2012 — — 600,000+ records (2008–2010 incidents)
Cataloged incident. Jun 2012. FTC sued Wyndham for failing to protect customer data. Three breaches (2008–2010) compromised 600k+ accounts. Russian hackers stole financial info; $10.6M+ fraudulent charges. Wyndham stored cards in plain text, used default admin passwords, lacked firewalls. First FTC suit for inadequate data security. Settled 2015 with 20-year compliance order. Exposed categories include Payment cards, financial info. BreachHistory cites approximately 600K+ affected records in this row. See the wyndham2012 and canonical BreachHistory entry.
2010 — — Wyndham Hotels & Resorts: International hotel group Wyndham Hotels and…
Unverified claim — treat actor counts cautiously. International hotel group Wyndham Hotels and Resorts (WHR) has suffered yet another serious data breach after hackers broke into its computer systems, stealing customer names and payment card information.UPDATE (05/18/2010): An open letter from Wyndham to its customers: www.wyndhamworldwide.com/customer_care/data-claim.cfmUPDATE (05/12/2011): Wyndham identified 42 additional New Hampshire residents who were affected by the 2010 breach. The total number of people affected by hacking incidents at Exposed categories include Personal information. BreachHistory cites approximately 500K+ affected records in this row. See the wyndham2010 and canonical BreachHistory entry.
2009 — — Wyndham Hotels & Resorts: In mid-September 2008, the company discovered that…
Cataloged incident. In mid-September 2008, the company discovered that a sophisticated hacker penetrated the computer systems of one of the hotels. By going through the centralized network connection, the hacker was then able to access and download information from several, but not all, of the other WHR properties and create a unique file containing payment card information of a small percentage of WHR customers. Potentially exposed throu Exposed categories include Personal information. BreachHistory cites approximately 21K+ affected records in this row. See the wyndham2009 and canonical BreachHistory entry.
Patterns and analysis
- Credential theft and social engineering — appears across multiple Wyndham Hotels & Resorts catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Bookmark the Wyndham Hotels & Resorts company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/wyndham · Latest: wyndham2014.
Sources: BreachHistory catalog (5 rows for Wyndham Hotels & Resorts), company and regulator disclosures cited in individual breach records.