Data breach
Waterford Hotel Group
- Records
- 142,593
- Breach date
- 11 May 2026Estimated
- Added
- 5 September 2026
What was exposed
11 types of data · 4 put you at serious risk
- Names142,593
- Phone numbers115,101
- Street addresses104,925
- Email addresses87,089
- Dates of birth37,219
- Social security numbers22,548
- Bank account numbers19
- Vehicle VINs19
- Driving licence numbers7
- Passport numbers7
- Licence plates5
About this breach
The investigation team has indexed a data breach affecting Waterford Hotel Group, a hospitality company that manages hotels and conference centers. According to our investigation team, the ransomware and extortion group Interlock claimed responsibility for the attack, with an estimated attack date of May 11, 2026. The same date matches Interlock's public leak site, where the group listed Waterford Hotel Group and said it was publishing a dataset covering the hotel chain and its other divisions, including personal and confidential data, partner contact information, and financial information. Interlock did not state a ransom amount.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names: 142,593 records
Phone numbers: 115,101 records
Street addresses: 104,925 records
Email addresses: 87,089 records
Dates of birth: 37,219 records
Social Security numbers: 22,548 records
Bank account numbers: 19 records
Vehicle identification numbers (VINs): 19 records
Vehicle license plates: 5 records
Passport numbers: 7 records
Driver's license numbers: 7 records
In total, the indexed dataset contains 142,593 rows.
Not every individual is affected by every type of data listed here.
The presence of Social Security numbers is notable. These identifiers cannot be changed like a password, which makes them valuable for identity fraud. The smaller counts of passport, driver's license, and bank account records suggest these may belong to a subset of individuals, such as employees, guests, or business partners, but the available sources do not explain who these records belong to.
What Are the Potential Risks for Affected Individuals?
The combination of names, addresses, phone numbers, emails, and dates of birth gives criminals the raw material for targeted phishing and social engineering. Messages that reference real personal details are more convincing and harder to dismiss.
For the more than 22,000 individuals whose Social Security numbers appear in the data, the risks are more serious. Those numbers can be used to open fraudulent credit accounts, file fake tax returns, or commit other forms of identity theft that can take months to untangle.
The small number of bank account records carries a direct financial risk if accurate, though it is not clear from available sources whether full account details were exposed. People whose passport or driver's license numbers were exposed could face document-related fraud, such as fraudulent applications using their identity details.
What Should You Do If You Were Affected?
If you believe your information was involved, take these steps:
Check whether your email appears in the breach.
Place a fraud alert or credit freeze. Contact one of the three major US credit bureaus (Equifax, Experian, or TransUnion). A freeze restricts access to your credit file and is free.
Monitor your credit reports. You can request free reports from each bureau at AnnualCreditReport.com and watch for accounts you did not open.
Watch for phishing. Be cautious with calls, texts, or emails that reference hotel stays, bookings, or personal details. Do not click links or share information in response to unexpected contact.
Consider an IRS IP PIN. If your Social Security number was exposed, an Identity Protection PIN from the IRS can help prevent fraudulent tax return filings.
Update financial account access. If you think your bank details were exposed, ask your bank to watch for unusual activity and consider changing account credentials.
