Omni Hotels & Resorts was hit by a cyberattack in late March 2024. Reservation systems, hotel door locks and payment systems were affected. The Daixin Team claimed responsibility and said it held data covering Omni guests going back to 2017.
Seven Years Of Guests Is A Retention Decision
If the claim is accurate, the exposed population is not current guests. It is everyone who stayed across seven years, most of whom have no ongoing relationship with the chain and will not be expecting a notification from it.
This recurs constantly: Mr Cooper held every former mortgage customer, Neopets held accounts opened by children two decades earlier. Retention past the relationship converts a completed transaction into a permanent liability held on someone else’s behalf.
Door Locks Are On The Network
The reported effect on room locks is the detail worth keeping. A hotel’s physical access control is an IT system, and it fails when IT fails.
Graded medium: the seven-year claim originates with the operation that made it, and Omni has not published a record count or confirmed the scope.
Compiled from public reporting and the operation’s claims, listed below. The 2017 date and the scope of guest records are the attacker’s claim, not the company’s. No record count has been published. Corrections: corrections@forensicpost.com.
- Omni Hotels confirms cyberattack behind IT outageBleepingComputer