Home · Briefs · CTI Weekly Summary — 2026-W20 (May 11 – May 17, 2026)
BWH Hotels — 181-day unauthorised access to guest-reservation web application
From CTI Weekly Summary — 2026-W20 (May 11 – May 17, 2026) · published 2026-05-17
Six EU brands (Best Western, WorldHotels, Sure Hotels and three sub-brands) in scope; 181-day dwell time indicates absent application-tier telemetry on the affected reservation web application. EU regulatory scope: GDPR Article 33 / 34 obligations for the six EU-brand reservation systems holding EU PII. The defender's learning: audit which guest-facing / citizen-facing web applications have no structured access-event telemetry into the SIEM (daily 2026-05-13).