Data breach
trumphotels.com
- Records
- 164,908
- Breach date
- 1 January 2025Estimated
- Added
- 17 March 2025
What was exposed
2 types of data
- Names164,908
- Email addresses151,178
About this breach
A data set containing more than 164,000 records tied to trumphotels.com, the website of the Trump Hotels brand, surfaced on the hacker forum BreachForums in early February 2025. A user going by the name FutureSeeker, described by Cybernews as little known and only active on the forum since August 2024, posted what appears to be a sample of the data and claimed to have taken 164,910 records from the site. The malware research group vx-underground drew wider attention to the claim on February 4, 2025, saying the thief appeared to have pulled records from the Trump Hotels email notification system, the service used to remind and verify reservation details for guests.
According to our investigation team, the indexed data set contains 164,908 rows. Cybernews, which reviewed a sample rather than the full set, reported that the records include full names, email addresses, account creation dates and timestamps of communications. The data reportedly spans January 18, 2018 to January 15, 2025. No claim of responsibility has been attached to a named group beyond the forum post itself, and the type of the attack has not been established.
What Information Was Compromised?
Our analysis found the following data types in this breach: names and email addresses. Our investigation team counted 164,908 records containing names and 151,178 containing email addresses.
Cybernews reported that the sample also included account creation dates and communication timestamps, suggesting the records came from a marketing or reservation-reminder email database rather than a guest booking system.
Not every individual is affected by every type of data listed here.
Reporters and independent reviewers noted that the data set did not appear to include information about guests actually staying at Trump-operated properties, such as reservation dates, check-in and departure records, or financial information. The records indexed so far do not include passwords or payment card data. That limits the direct harm, but the combination of real names and email addresses still carries risk for the people involved.
What Are the Potential Risks for Affected Individuals?
The most likely misuse is phishing. People whose names and email addresses appear in a hotel-branded database can be targeted with emails that look like legitimate reservation confirmations, loyalty offers or customer service messages. Because the sender can quote a real name, these messages are more convincing than generic spam.
The data can also feed credential attacks against other accounts. Even without passwords in this data set, attackers routinely pair leaked email lists with passwords taken from other breaches, betting that people reuse the same login details across sites. Individuals with public or politically sensitive profiles may face additional targeting, given the prominence of the brand involved.
There is no evidence in the reviewed sources that financial data was exposed. Anyone who notices unusual activity related to a Trump Hotels reservation or email subscription should treat that as a separate concern and report it.
What Should You Do If You Were Affected?
Be skeptical of emails claiming to confirm or update a Trump Hotels reservation, even if they use your name. Avoid clicking links in unexpected messages.
If you used the same password for trumphotels.com or any related account as elsewhere, change it now and choose a unique password for each account.
Turn on two-factor authentication where it is offered, especially for your email account, which protects access to everything else.
Watch your inbox for signs that someone else signed up for or changed email preferences connected to your address.
