01Summary
In late March 2024, Omni Hotels & Resorts suffered a ransomware attack that brought down their central reservation system, property management platforms, and electronic key card encoding systems. The attack forced all 50+ Omni properties to operate in manual mode. Guests were locked out of their rooms when electronic key cards failed to encode. The reservation system outage meant new bookings could not be processed. The attackers exfiltrated guest data including names, addresses, credit card information, and loyalty program details. The disruption lasted for several weeks.
02Background
Omni Hotels & Resorts is a privately held luxury hotel chain founded in 1958, operating over 50 properties throughout North America including hotels, resorts, and golf properties.
03Key revelations
- 01Entire 50+ property hotel chain forced to operate manually for weeks
- 02Electronic key card systems rendered inoperable
- 03Guest credit card data stolen
- 04Backup systems also encrypted
04Technical analysis
The ransomware targeted Omni's central property management system controlling reservations, billing, and room access across all properties. Attackers gained access through a compromised VPN account with elevated privileges. The encryption affected both production systems and backup servers.
- Attack vector
- Compromised VPN account with privilege escalation
- Attack method
- Ransomware encryption with data exfiltration (double extortion)
- Initial access
- Compromised VPN credentials
- Exfiltration
- Data exfiltration prior to ransomware deployment
05Threat actor
Professional ransomware group with focus on hospitality sector. Demonstrated patience in network reconnaissance before deploying encryption across all systems including backups.
Attribution sources
- BleepingComputer
- Media reports
06Victims and impact
Countries affected
- United States
- Canada
07Data exposed
Data types
- Guest names
- Addresses
- Phone numbers
- Email addresses
- Credit card numbers
- Loyalty program details
- Reservation histories
08Financial damage
Revenue losses from inability to process reservations for weeks. IT remediation costs. Legal exposure from guest data compromise.
09Timeline
- 2024-03-20Ransomware attack detected; all systems taken offline
- 2024-03-21All 50+ properties operating manually
- 2024-03-25Guest data breach confirmed
- 2024-04-15Systems partially restored
- 2024-04-30Full restoration completed
10Reaction and fallout
Public reaction
Widespread frustration among guests unable to check in, check out, or access their rooms. Media coverage highlighted hotel chain operating with pen and paper.
Political impact
Industry-wide reviews of hospitality cybersecurity practices.
11Legal
Potential class-action lawsuits from affected guests. State attorney general investigations.
Civil lawsuits
- Potential class-action for guest data compromise
12Aftermath
Policy changes
- Hospitality industry cybersecurity guidelines strengthened
Security improvements
- Network segmentation between property management and corporate systems
- Enhanced backup protection including offline and immutable backups
- Mandatory MFA for all remote access
13Significance and legacy
Significance
Demonstrated the catastrophic operational impact of ransomware on the hospitality industry, where digital systems control everything from room access to payments.
Legacy
Omni Hotels became a textbook example of ransomware operational disruption in hospitality, driving industry-wide adoption of offline backups.
14Disclosure and media
- Authentication
- Breach notification and media coverage
Publishing organisations
- BleepingComputer
15Field notes
- 01Omni had to use physical cardboard key cards as backups during the outage
- 02Some hotels hired additional temporary staff just to escort guests to their rooms with master keys
16Resolution
Systems restored over 4-6 weeks. Guest notification completed. Credit monitoring offered.
17Sources
References
- [1]BleepingComputer: Omni Hotels ransomware attack
- [2]Hospitality Tech: Omni breach analysis









