Cyber risk resilience quarterly : threat intelligence for hotel, restaurants and tourism sectors. Q2 2026

Paraskevas, Alexandros ORCID logoORCID: https://orcid.org/0000-0003-1556-5293 (2026) Cyber risk resilience quarterly : threat intelligence for hotel, restaurants and tourism sectors. Q2 2026. Technical Report. University of West london, London.

[thumbnail of Cyber Risk Resilience Quarterly Q2 2026.pdf]
Preview
PDF
Cyber Risk Resilience Quarterly Q2 2026.pdf - Published Version

Download (696kB) | Preview

Abstract

The second quarter of 2026 produced a high volume of cyberattacks against hotel groups, restaurant and food service operators, tourism businesses and their technology providers. This edition documents twenty confirmed and claimed incidents, together with two first quarter attacks that reached notification inside the period.

The quarter turned on the platform. Criminals reached guest records through cloud customer relationship systems, shared booking software and vendor‑operated storage. The largest breach began with an employee granting access to somebody who asked for it. Attackers moved to extortion without encryption. In one case, they achieved extortion without any intrusion at all.

None of the attacks this quarter took payment terminals, ticketing systems or building systems offline. That is a marked change from the first quarter.

The report maps each incident against five stages of a typical intrusion. It assesses the groups responsible. It examines how breaches were monetised and sets out legal exposure across thirteen jurisdictions. The recommendations follow the control failures observed.

Item Type: Report (Technical Report)
Additional Information: © 2026 International Centre for Hospitality and Aviation Resilience Management, University of West London. This report is provided for general information and situational awareness only. It does not constitute legal, financial, or professional advice, and should not be relied upon as the sole basis for any decision. Incident data is drawn from regulatory filings, public disclosures, and open and closed source intelligence, and should be verified before operational use.
Subjects: Computing > Information security > Cyber security
Computing > Intelligent systems
Hospitality and tourism
Date Deposited: 03 Aug 2026
Dates:
Date
Publication status
15 July 2026
Published Online
School, department or research centre: London Geller College of Hospitality and Tourism
URI: https://repository.uwl.ac.uk/id/eprint/15270
Sustainable Development Goals: Goal 9: Industry, Innovation, and Infrastructure

Downloads

Downloads per month over past year

Actions (admin access)

View Item

Menu