
Hyatt
Data Breach on January 15, 2026
| Data Breach Report | |||
|---|---|---|---|
| Victim | hyatt.com | ||
| Threat Actor | NightSpire | ||
| Date Discovered | Jan 15, 2026 | ||
| Description | Hyatt is a global hospitality company based in the USA (Illinois) that operates, franchises and licenses a broad portfolio of branded hotels, resorts, residence properties and vacation-ownership experiences worldwide. | ||
| Leak Size | 48.5GB |
Credential Exposure for hyatt.com
We've indexed 15,881 @hyatt.com accounts from external breaches, plus 16,377 credentials for hyatt.com itself.
Last checked Aug 23, 2026
| @hyatt.com addresses from external breaches | |
|---|---|
| Third-party breaches | 15,065 accounts · across 984 breaches · 13,847 with a plaintext password · most recent Apr 19, 2026 |
| Combo lists | 4,346 accounts · most recent Aug 22, 2026 |
| Phishing pages | 26 accounts · most recent Aug 13, 2026 |
| Passwords for hyatt.com accounts | |
|---|---|
| Combo lists | 12,820 logins · most recent Aug 23, 2026 |
| Infostealer logs | 5,238 logins · 3,783 infected devices · most recent Aug 8, 2026 |
Logins may belong to customers or to staff, and the data doesn't say which. None of this is necessarily connected to the ransomware attack above.
Is your organization next?
Hyatt was breached. Check if your company's credentials have been exposed in this or other data breaches.
Check your exposure →Continuous dark web monitoring alerts you when we find leaked credentials or session tokens for your company.