EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware/omni-hotels-ransomware-2024
103/430

File EL-0328HighResolvedRansomware / Ransomware with Operational Disruption

Omni Hotels Ransomware Attack

Also filed as Omni Hotels & Resorts Data Breach · Omni Hospitality Ransomware

Omni Hotels & Resorts, one of North America's largest privately owned hotel chains operating over 50 properties, was hit by a devastating ransomware attack in March 2024 that crippled reservation systems, key card encoding, and property management infrastructure for weeks.

  • #hospitality
  • #hotels
  • #ransomware
  • #guest-data
  • #credit-cards
  • #operations-disrupted
  • #tourism
Notoriety8/10
Event
20 Mar 2024
Disclosed
25 Mar 2024
Target
Omni Hotels & Resorts
Scale
500K people
Status
Resolved

01Summary

In late March 2024, Omni Hotels & Resorts suffered a ransomware attack that brought down their central reservation system, property management platforms, and electronic key card encoding systems. The attack forced all 50+ Omni properties to operate in manual mode. Guests were locked out of their rooms when electronic key cards failed to encode. The reservation system outage meant new bookings could not be processed. The attackers exfiltrated guest data including names, addresses, credit card information, and loyalty program details. The disruption lasted for several weeks.

02Background

Omni Hotels & Resorts is a privately held luxury hotel chain founded in 1958, operating over 50 properties throughout North America including hotels, resorts, and golf properties.

03Key revelations

  1. 01Entire 50+ property hotel chain forced to operate manually for weeks
  2. 02Electronic key card systems rendered inoperable
  3. 03Guest credit card data stolen
  4. 04Backup systems also encrypted

04Technical analysis

The ransomware targeted Omni's central property management system controlling reservations, billing, and room access across all properties. Attackers gained access through a compromised VPN account with elevated privileges. The encryption affected both production systems and backup servers.

Attack vector
Compromised VPN account with privilege escalation
Attack method
Ransomware encryption with data exfiltration (double extortion)
Initial access
Compromised VPN credentials
Exfiltration
Data exfiltration prior to ransomware deployment

05Threat actor

Professional ransomware group with focus on hospitality sector. Demonstrated patience in network reconnaissance before deploying encryption across all systems including backups.

Attribution sources

  • BleepingComputer
  • Media reports

06Victims and impact

Countries affected

  • United States
  • Canada

07Data exposed

Data types

  • Guest names
  • Addresses
  • Phone numbers
  • Email addresses
  • Credit card numbers
  • Loyalty program details
  • Reservation histories

08Financial damage

Revenue losses from inability to process reservations for weeks. IT remediation costs. Legal exposure from guest data compromise.

09Timeline

  1. 2024-03-20Ransomware attack detected; all systems taken offline
  2. 2024-03-21All 50+ properties operating manually
  3. 2024-03-25Guest data breach confirmed
  4. 2024-04-15Systems partially restored
  5. 2024-04-30Full restoration completed

10Reaction and fallout

Public reaction

Widespread frustration among guests unable to check in, check out, or access their rooms. Media coverage highlighted hotel chain operating with pen and paper.

Political impact

Industry-wide reviews of hospitality cybersecurity practices.

11Legal

Potential class-action lawsuits from affected guests. State attorney general investigations.

Civil lawsuits

  • Potential class-action for guest data compromise

12Aftermath

Policy changes

  • Hospitality industry cybersecurity guidelines strengthened

Security improvements

  • Network segmentation between property management and corporate systems
  • Enhanced backup protection including offline and immutable backups
  • Mandatory MFA for all remote access

13Significance and legacy

Significance

Demonstrated the catastrophic operational impact of ransomware on the hospitality industry, where digital systems control everything from room access to payments.

Legacy

Omni Hotels became a textbook example of ransomware operational disruption in hospitality, driving industry-wide adoption of offline backups.

14Disclosure and media

Authentication
Breach notification and media coverage

Publishing organisations

  • BleepingComputer

15Field notes

  1. 01Omni had to use physical cardboard key cards as backups during the outage
  2. 02Some hotels hired additional temporary staff just to escort guests to their rooms with master keys

16Resolution

Systems restored over 4-6 weeks. Guest notification completed. Credit monitoring offered.

17Sources

References

  1. [1]BleepingComputer: Omni Hotels ransomware attack
  2. [2]Hospitality Tech: Omni breach analysis
Fact sheetEL-0328

Dates

Event
20 Mar 2024
Started
20 Mar 2024
Duration
41 days
Discovered
20 Mar 2024
Disclosed
25 Mar 2024
Resolved
30 Apr 2024
Ongoing
No

Target

Organisation
Omni Hotels Management Corporation
Type
Corporation
Sector
Hospitality / Hotels
Country
United States

Actor

Type
Criminal Gang
Motivation
Financial gain through ransomware extortion and theft of guest credit card data and personal information.
Attribution
Low
Arrested
No
Convicted
No

Data

People
500,000
Records
500,000
Sensitivity
High
Published
Yes
Sold (dark web)
No

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.