ctipilot.ch
← Back to Weekly 2026-W20
NOTABLEincident

BWH Hotels — 181-day unauthorised access to guest-reservation web application

discovered 2026-05-11 05:00 UTCrun 2026-W20-71c96b251 sourcesingle-source

Six EU brands (Best Western, WorldHotels, Sure Hotels and three sub-brands) in scope; 181-day dwell time indicates absent application-tier telemetry on the affected reservation web application. EU regulatory scope: GDPR Article 33 / 34 obligations for the six EU-brand reservation systems holding EU PII. The defender's learning: audit which guest-facing / citizen-facing web applications have no structured access-event telemetry into the SIEM (daily 2026-05-13).

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.