WYNDHAM HOTELS & RESORTS, INC.
ent_019e57eb43f451736946198e3856f063
Disclosures
4
SEC 10-K Item 1C · State AG · 3 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
201
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- WYNDHAM HOTELS & RESORTS, INC.
- Normalized
- wyndham hotels resorts— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300FE3MQ4RVXXC673
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-19
Wyndham Hotels & Resorts filed its 10-K Item 1C disclosing no material cybersecurity incidents as of the filing date. The filing details a robust cybersecurity program including threat intelligence, a hybrid SOC, and an Information Risk Committee. It confirms no known material risks affecting financial condition, though it notes prior incidents occurred before a Spin-Off.
- ⛰️New Hampshire State AGas victim2009-08-21
Wyndham Hotels and Resorts, LLC submitted a supplemental notice to the New Hampshire Attorney General regarding a data security incident affecting approximately 201 New Hampshire residents. The breach involved the unauthorized access of credit card numbers and transactional data from March 29 to May 10, 2009, via a sophisticated hacker. Wyndham retained forensic investigators, notified law enforcement and payment networks, and provided one year of credit monitoring services to affected individuals.
- ⛰️New Hampshire State AGas victim2008-11-23
Wyndham Hotels and Resorts notified New Hampshire AG in December 2008 regarding unauthorized access to systems at certain branded hotels. Compromised data included credit/debit card numbers, expiration dates, and names. Wyndham terminated access, notified law enforcement and payment networks, and offered one year of free credit monitoring.
- 🌺Hawaii State AGas victim2008-10-14
Wyndham Hotels and Resorts, LLC reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2008/10.14. Breach type: Hackers/Unauthorized Access. 1,000 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.