HackingStolen CredentialsPhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
The Aviator Hotel (Farnborough) Limited
bd_d3fd203e4e346e6c · schema v1 · pii pii-v1
Full breach record for The Aviator Hotel (Farnborough) Limited →The Aviator Hotel (Farnborough) Limited reported a breach of its Rezlynx booking platform where unauthorized access was gained using stolen credentials of a Head Server. The incident affected 1,428 guests (1 in New Hampshire), exposing names, emails, phone numbers, and reservation details. The actor subsequently sent phishing emails to victims. The incident was contained on March 23, 2026, and notifications were sent on March 27, 2026.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,428 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/aviator-hotel-farnborough-20260421.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2026
- Raw hash
- 4cfa3ee852159612243df1416c05beee73479898c7ebc39c1a18d875283e8d30
Reporting entity
- Name
- The Aviator Hotel (Farnborough) Limitednorm: the aviator hotel farnborough
Victim entity
- Name
- The Aviator Hotel (Farnborough) Limitednorm: the aviator hotel farnborough
Incident
- Discovered
- Mar 23, 2026
- Materiality determined
- —
- Notification sent
- Mar 27, 2026
- Affected individuals
- 1,428
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the National Crime Agency in the UK
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.