
A significant data breach has compromised Otelier, a leading hotel management platform, exposing millions of hotel guests’ personal information. The breach, which targeted the Amazon S3 cloud storage used by Otelier, affected prominent hotel brands such as Marriott, Hilton, and Hyatt. Threat actors reportedly accessed 7.8 terabytes of sensitive data, including reservation details, guest transactions, and internal records.
The breach began in July 2024 and persisted through October, with attackers leveraging stolen employee credentials to infiltrate Otelier’s Atlassian server. These credentials, obtained via information-stealing malware, allowed the hackers to scrape additional access details and gain entry to Otelier’s cloud storage. The attackers downloaded extensive datasets, including hotel nightly reports, shift audits, and accounting documents, many of which involved Marriott properties.
Atelier, formerly MyDigitalOffice, confirmed the breach and stated it had engaged top-tier cybersecurity experts to investigate and enhance its security protocols. “Our top priority is to safeguard our customers while enhancing the security of our systems to prevent future issues,” the company stated. It ensured that unauthorized access had been terminated and affected accounts were disabled.
The incident has had far-reaching implications for Otelier’s clients. Marriott, for example, suspended automated services provided by Otelier pending the completion of the investigation. A Marriott spokesperson confirmed, “None of our systems were breached in this attack, and we have taken appropriate precautions.”
While Otelier has remained tight-lipped about specific details, cybersecurity expert Troy Hunt, founder of Have I Been Pwned, reported receiving an extensive dataset from the breach. This included a reservations table with 39 million entries and a user table with 212 million rows. However, the dataset contained 1.3 million unique email addresses due to repetition.
The compromised data includes names, addresses, phone numbers, and email addresses of hotel guests, but passwords and billing information were not stolen. Nevertheless, cybersecurity experts warn of potential phishing attacks targeting individuals using the exposed information. Guests are advised to remain vigilant and report suspicious communications.
The attackers also attempted to extort Marriott, mistakenly believing the compromised data storage belonged directly to the hotel chain. They left ransom notes demanding cryptocurrency payments to prevent data leaks, but Marriott did not engage with the threat actors. The attackers lost access in September after Otelier rotated credentials.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543