SHINDO2

Hotel Nikko Princess Kyoto

Account takeoverSize not disclosed

POSSIBLE LEAKPhone number / Full nameClosed (final report)

Open in the live monitor ▶
Disclosed
Mar 19, 2026
Leak
Leak possible
Type
Account takeover
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName
ContactPhone number
Transactions & activityCheck-in date and room charge

Not leaked

  • Credit card data was not included

Who is affected

  • Guests who booked via Expedia

Cause

Unauthorized login to the Expedia admin account; a third party posing as hotel staff asked guests for card data via WhatsApp

Timeline

  1. First disclosure

Response

  • Blocked the entry point
  • Phishing warning

Blocked the unauthorized login; warned that neither the hotel nor Expedia asks for card data by email or chat

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources