← BWH Hotels

2026 BWH Hotels (Best Western) — guest reservation web app; Oct 2025–Apr 2026 access window

2026 Unknown records affected Share on X

Data compromised

Guest contact information and reservation metadata; no payment or bank details per BWH notifications

Technical writeup

BWH Hotels—the parent of Best Western Hotels & Resorts, WorldHotels, and Sure Hotels—told guests in May 2026 that on April 22, 2026 it identified unauthorized activity in a web application storing certain reservation data, with exposed records reaching back to October 14, 2025. Notification emails summarized by The Register and BWH's own letter (signed by CTO Bill Ryan) stated names, email addresses, phone numbers, postal addresses, reservation numbers, stay dates, and special requests were involved, while payment card and bank data were not stored in the affected application. UK press in June 2026 (Liverpool Echo, Daily Express) amplified guest warnings ahead of summer travel, noting reservation metadata lets scammers reference real hotel names, stay dates, and booking references in convincing SMS, WhatsApp, and email lures—even without card numbers. The company had not published a consolidated victim count in indexed English trade press at catalog time. BreachHistory tracks hospitality PII suitable for targeted phishing around upcoming stays.

Root cause

Unauthorized access to guest-reservation web application (detection April 22, 2026; data window from October 14, 2025)

References