Desk live·
ForensicPost
Cloud/Hospitality/File 25-0123b

Otelier Breach Compromised Data Tied to Marriott, Hilton and Hyatt

A threat actor breached the Otelier hotel management platform in January 2025, compromising customer data associated with brands including Marriott, Hilton and Hyatt.

Constructed geometry · not a chart of case data
TargetOtelier
ActorUnattributed
D. Kennedy12 min readConfidence: medium2 sources reviewed

A threat actor breached Otelier, a hotel management platform, in January 2025, compromising customer data associated with hotel brands including Marriott, Hilton and Hyatt.

The Guest Chose A Hotel, Not A Platform

This is the concentration structure the corpus files constantly — Marquis at 25-0814, Chain IQ at 25-0613, SitusAMC at 25-1112b — appearing in a sector where the brand relationship is unusually strong.

A guest who books a Marriott believes they are dealing with Marriott. The property may be independently owned and operated under franchise, using a management platform selected by the operator, which holds the reservation record. Three organisations the guest never chose, between the brand on the door and the data.

And A Stay Record Is A Location Record

This desk filed at 25-0725 that lodging appeared on a state-linked target list alongside telecom, government, transportation and military, and argued that a hotel record is the join key converting location-adjacent data into confirmed physical presence.

That file described a collection logic without a named incident behind it. This is a named hospitality platform incident, and it demonstrates that the data sits somewhere reachable — which is the part the earlier argument had to assume.

The corpus is not suggesting any such purpose here. The point is that the same record supports entirely different uses depending on who holds it, and a hotel operator’s risk assessment considers payment fraud.

Franchise Structures Make Notification Incoherent

Where a brand, an owner, an operator and a platform are four separate entities, the question of who is the controller — and therefore who notifies — is genuinely difficult.

The corpus recorded the same fragmentation at 25-0710 for LVMH brands and at 25-0615 for a grocery parent company. Graded medium: the affected volume and the mechanism are not established in the material we reviewed.

How we reported this

Compiled from published reporting, listed below. Affected volume, mechanism and the relationship between the platform and each named brand are not established. Corrections: corrections@forensicpost.com.

Sources
  1. Cyberattacks that devastated hospitalityAsimily
  2. Cyberattacks are draining millions from the hospitality industryHelp Net Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary