- 84% of hotel properties experienced at least one cyber incident in the past year
- Average breach costs in hospitality now exceed $4 million per incident
- 82% of detected intrusions use stolen credentials rather than malware
- 55% of hotel properties suffered an outage caused by an external vendor or partner
- 48% of hotel IT leaders doubt front-line staff can identify AI-generated phishing
- Five confirmed breaches from 2025 and 2026 show how the attack patterns translate into real incidents
The numbers behind the 2026 threat picture
Among hotel properties surveyed in 2025 hospitality security research:
- 84% experienced at least one cyber incident during the year
- 82% recorded a successful intrusion, with most targeted more than once per season
- 90% of North American hotel IT and security leaders reported at least one attempted attack
- 58% of properties faced five or more attacks in a single peak season
- 44% of breached properties suffered 12 or more hours of critical system downtime
The financial picture matches the frequency data. Average enterprise breach costs in hospitality exceed $4 million per incident. For properties hit by ransomware that targets operations rather than data alone, the number climbs further when check-in systems, reservation platforms, and keyless entry all go offline at once during a high-occupancy period.
How the attacks have changed
Credentials over malware
82% of security detections in the hospitality sector are now malware-free. Attackers obtain leaked, reused, or phished employee credentials and log into PMS platforms, booking integrations, and back-office networks. They reach high-value systems without triggering antivirus tools designed to catch file-based threats.
AI-generated phishing at scale
Nearly half of hotel IT and security leaders say they doubt their front-line staff could identify advanced AI-generated phishing or deepfake-based social engineering. AI lets attackers produce convincing reservation correspondence, booking confirmations, and manager impersonations at a volume and quality that human review struggles to catch. Front-desk staff who process hundreds of guest communications per shift cannot manually screen each one for AI generation.
Operational disruption as the objective
Ransomware-as-a-Service groups have shifted from data encryption alone to operational sabotage. The objective is to halt reservations, disable check-in, and lock keyless entry systems until payment resolves the disruption. For a hotel running at high occupancy during peak season, a 12-hour outage causes compounding damage to revenue and guest experience before any ransom negotiation begins. Many groups also publish stolen data on leak sites regardless of whether the ransom is paid, removing payment as a way to contain the breach's consequences.
The infrastructure that widens the attack surface
Hotels connect PMS platforms, POS terminals, booking integrations, guest Wi-Fi, smart room devices, and vendor systems into a single operational network. Each category below is a confirmed entry point or lateral movement path.
Confirmed breaches, 2025 and 2026
Attackers accessed customer booking data through compromised hotel partner accounts connected to a major global travel platform's central reservation system. The exposed data covered names, email addresses, phone numbers, and detailed itinerary information. Attackers converted this data within hours into targeted phishing and SMS campaigns, contacting guests directly with instructions to update payment details through fraudulent pages.
The platform's parent company received a €475,000 regulatory fine for reporting the breach 22 days after the exposure was confirmed. The incident illustrates the trust exploitation model: attackers used real booking data to make the fraud convincing.
A large hotel umbrella group managing multiple brands disclosed that attackers had maintained undetected access to a core web application for six months before discovery. The exposed data included reservation numbers, names, email addresses, phone numbers, home addresses, dates of stay, and specific guest requests. Payment card details were not in scope.
The six-month dwell time gave attackers enough guest contact profile depth to run targeted fraud against frequent guests long after access ended. Hotels without dark web monitoring and anomaly detection on application access logs give attackers months of undetected access.
An apartment hotel chain operating across multiple countries suffered a breach that originated in a vulnerability within a third-party service provider's database system. The exposed records covered historical customer data including names, contact information, and dates of birth. Vendor-side code and shared infrastructure created the entry point, exposing customer records across the chain's full history.
A hospitality management company overseeing a portfolio of luxury and branded resort properties experienced a network breach affecting internal assets, employee documentation, and guest data. Data breach notifications went out to affected individuals through early 2026, accompanied by complimentary identity monitoring to limit downstream fraud exposure.
Security researchers identified coordinated, AI-enhanced phishing campaigns targeting hotel front-desk workers across European and Latin American properties. Attackers sent fake reservation cancellation requests to staff. When employees opened the attachments, a realistic fabricated Blue Screen of Death appeared, claiming a fatal system error. The screen directed staff to run a repair tool that deployed information-stealing code directly into POS and Property Management System infrastructure.
The campaign exploited two vulnerabilities simultaneously: front-desk staff's familiarity with reservation communications and their reflex to resolve apparent system errors quickly. Standard phishing awareness training covers neither fabricated error screens nor spoofed reservation requests.
Where the defence gap sits
The gap between what hotels deploy and what the current threat level requires is measurable. Around 70% of hotel operators run firewalls and standard antivirus tools. Fewer than half run active vulnerability scanning, dark web monitoring, or penetration testing.
Most hotels have perimeter controls that stop the threats most attackers have already moved past. Credential-based intrusions, vendor-side compromise, and AI-generated phishing all operate in the space between basic perimeter tools and the more active monitoring that would detect them.
Three controls appear most frequently as absent when hospitality breaches are reviewed after the fact:
- Active vulnerability scanning on PMS, POS, and booking platform integrations, run at a frequency that matches the change rate of those systems
- Dark web monitoring to identify compromised employee credentials before attackers use them to log in
- Social engineering training calibrated to AI-generated content, not generic phishing templates from five years ago
Why the gap persists
Five structural factors keep most hotel properties below the threshold their threat exposure requires.
Staffing
Hospitality competes against financial services, technology, and healthcare for the same pool of security professionals, on lower salary budgets. 80% of hotels in recent industry surveys identify recruitment and retention of qualified IT and cybersecurity staff as a persistent problem. The result is that security responsibilities fall to IT generalists, front-desk managers, or no dedicated security function at all.
Budget
70% of hospitality IT staff cite insufficient budget as the primary barrier to improving their security posture. Security investment in hospitality tends to follow incidents rather than anticipate them. A hotel that has not been breached recently directs capital towards guest-facing technology before infrastructure hardening. After a breach, that pattern reverses, and the spend required is much higher and happens under pressure.
Legacy systems
70% of hotels run at least one legacy system (property management software, POS platforms, or network infrastructure) that vendors no longer actively patch. These systems represent permanent attack surface. Replacing them requires capital, downtime, and migration risk that most properties defer year after year. Attackers target known vulnerabilities in widely-used hospitality software because the patch cycle is slow.
Loyalty programme exposure
Loyalty and rewards accounts hold real monetary value: points convert to flights, stays, and gift cards. They also store personal and travel data across years of guest history. This makes them a persistent phishing target separate from the PMS. Credential stuffing attacks against loyalty programmes run continuously, using breached credential lists from other sectors. Hotels that treat loyalty security as a marketing concern rather than a security concern create exposure their IT teams are not positioned to monitor.
Vendor contract gaps
Most hotel supplier agreements include no meaningful cybersecurity obligations, no audit rights, and no breach notification timelines. Yet vendor access to PMS, booking platforms, and loyalty systems is a confirmed entry point in multiple 2025 and 2026 incidents. Hotels that accept vendor assurances without contractual teeth have no way to verify the security posture of systems their guests' data flows through.
What 2026 adds to the threat profile
Deepfake social engineering has moved from concept to operational use. Attackers generate convincing voice or video impersonating hotel executives or IT support to direct staff into actions that install malware or hand over access credentials. Controls designed for text phishing do not address this vector. Front-desk staff, who face the highest targeting volume, receive the least security training.
RaaS groups now publish stolen hotel data on leak sites regardless of whether the ransom is paid. Payment no longer prevents disclosure. Payment no longer prevents disclosure: notification to the ICO and affected guests is required whether or not the encrypted data is recovered.
Where to start
For hotels and hospitality portfolios, start by mapping which controls from the list above are absent and which attack surfaces from the infrastructure table go unmonitored. Our hospitality cybersecurity guide covers the specific attack surfaces and baseline security controls in more depth. For a direct view of your current security posture, the Cyvra Cybersecurity Assessment covers hotel environments and produces a prioritised action list rather than a generic report.