2026 Chekin / Gastrodat - automated hotel booking data theft affecting nearly 5M guests
Data compromised
Stay dates, reservation IDs, guest names, property addresses, internal safety flags, phone numbers, email addresses, dates and places of birth, and in some cases ID document details; compromised account credentials, plaintext passwords, and JWT tokens were also found on the threat-actor server
Technical writeup
Cybernews reported that researchers found an exposed server belonging to an unknown threat actor on March 24, 2026. The server contained roughly 6.5 GB of files, scripts, extraction logs, and structured dumps used to harvest booking data from hospitality platforms including Chekin and Gastrodat. Researchers said data was extracted from more than 170 facilities, involved roughly 400,000 separate bookings, and included nearly 5 million individuals, with some scripts apparently forwarding stolen data to Telegram in real time.
Root cause
Compromised hotel/host accounts and automated API scraping scripts targeting Chekin and Gastrodat booking platforms