A major hotel chain says a cyberattack that it believes has been ongoing for about six months has resulted in the exposure of some guests’ booking-related information. The company confirms that details potentially accessed in the incident can include guests’ names, email addresses, telephone numbers and/or home addresses, along with other reservation details. Multiple reports describe the potential risk that criminals could use the leaked information for follow-on fraud. Authorities and consumer-focused coverage urge affected guests to remain alert for phishing emails or scam messages that may reference personal booking details to appear more credible. The reports do not indicate that payment card data was necessarily involved, and the extent of the affected records appears to vary by guest. The hotel chain is working to understand the incident and address the security issue, while warning customers to monitor communications and take precautions if contacted unexpectedly. Guests are advised to be cautious and to verify the legitimacy of any messages before providing additional information.