Quick answer: Omni Hotels & Resorts said a March 2024 cyberattack stole customer names, email addresses, postal addresses and Select Guest loyalty information. Omni said the affected data did not include payment-card information, other financial information or Social Security numbers. The Daixin Team claimed responsibility and alleged a much larger record count, but those claims were not independently verified. If you used Omni, change any reused password, review your Select Guest account and verify any notification through Omni’s official contact channels.
What happened at Omni Hotels?
Omni Hotels & Resorts, the hotel and resort company—not Omni Healthcare, Omni Family Health or Omnicell—experienced a cyberattack in March 2024. According to contemporaneous reporting based on Omni’s statement, the company shut down systems on March 29 after identifying intruders. Systems were reportedly restored on April 8.
The outage affected the availability of hotel services as well as the confidentiality of customer information. Reports described hotel phone outages, Wi‑Fi problems, room keys that did not work and broader disruption to property systems. Omni’s customer-data confirmation became public in mid-April 2024.
Security coverage described the event as a ransomware incident because the Daixin Team claimed responsibility and listed Omni on its leak site. Omni’s public confirmation established that customer information was stolen, but it did not independently prove every detail of the attackers’ account.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Timeline
| Date | What is publicly reported |
|---|---|
| March 29, 2024 | Omni shut down systems after detecting intruders. |
| April 8, 2024 | Systems were reportedly restored. |
| April 14–16, 2024 | Omni’s stolen-data statement appeared publicly through the company and news coverage. |
| August 18, 2026 | Omni’s current press room did not prominently show a newer public update about this incident. |
What information was exposed?
Contemporaneous reporting attributed the following categories to Omni’s statement:
- Customer names
- Email addresses
- Postal addresses
- Select Guest loyalty-program information
Omni reportedly said the affected information did not include payment information, other financial information or Social Security numbers. That is a narrower statement than saying every type of financial or identity information was safe in every circumstance.
Omni’s privacy policy lists information the company may collect in ordinary interactions, including identifiers, contact details, loyalty data and, depending on the interaction, account-login details, driver’s-license or passport information and voluntarily supplied health information. Those general categories do not establish that passports, licenses, dates of birth or health information were stolen in this attack.
The reported scope is documented in TechCrunch’s account of Omni’s statement.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
Was it definitely ransomware, and how many people were affected?
The safest description is that the attack was reported as ransomware and that the Daixin Team claimed responsibility. The public evidence distinguishes that attacker claim from Omni’s confirmed statement that customer information was stolen.
Reports also mentioned a claim that about 3.5 million records were taken and that records for visitors dating back to 2017 were involved. Those figures came from the threat actor or reporting about the threat actor; they were not established as Omni’s confirmed count. Public reporting located for this incident does not provide an Omni-issued number of affected people, a reliable property-by-property list or proof that every Select Guest member was affected.
Rank #4
For attribution context, see SecurityWeek’s coverage. Do not treat a leak-site post as proof that Daixin carried out every part of the intrusion or that all Omni guests were included.
Which Omni properties and customers were affected?
Outages were reported across Omni properties, but the available public reporting does not establish a complete list of compromised hotels or identify every affected guest. It is therefore not supported to say that every Omni property, every Select Guest member or everyone who stayed after a particular date was exposed.
Best Value
If Omni sent you a direct notice, use that notice as the relevant determination for your account. If you are unsure, contact Omni through the official contact page. It lists Guest Relations at 1-800-809-OMNI and Select Guest support at 1-877-440-OMNI.
What the exposed data means for customers
Phishing and impersonation
Name and address information can make a fake message look credible. Scammers may mention a hotel, reservation, loyalty balance or travel date and then request a payment, gift card, loyalty transfer or “identity verification.” Do not click an unsolicited link or call a number supplied in an unexpected message. Open Omni’s website yourself and use its published contact details.
Select Guest account takeover
Loyalty information can be valuable even when payment data was not part of the reported incident. An attacker who obtains or guesses a reused password may change an email address, inspect reservations or attempt to move points. Review your profile, reservations, stored details, loyalty credits and recent activity.
Payment and identity-theft risk
Because Omni reportedly said payment and other financial information were not included, this incident alone does not establish that you must replace a card or freeze your credit. Continue reviewing card and bank statements: a card could have been misused during a hotel stay for reasons unrelated to this breach. A credit freeze becomes more urgent if Omni or another credible notice later says Social Security numbers or comparable government identifiers were involved, or if you see identity-theft activity.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhat customers should do now
- Verify any notification. Do not use links in unsolicited breach emails. Confirm the message independently through Omni’s official contact page.
- Change your Omni and Select Guest password. Use a long, unique password. Change it anywhere else you reused it, especially email and financial accounts. Enable multifactor authentication if the account offers it.
- Inspect your Select Guest account. Omni’s Select Guest FAQ explains online account access and lists [email protected] and 1-877-440-6664 for support. Check your email address, reservations, profile, loyalty credits and account activity.
- Watch for targeted fraud. Be skeptical of requests for payment, gift cards, loyalty transfers, password resets or identity documents that arrive by email, text or phone.
- Monitor payment accounts. Review statements and contact the issuer if you find an unauthorized transaction. Do not replace a card solely because of the publicly reported Omni data categories.
- Use a credit freeze when the facts justify it. Omni’s reported statement said Social Security numbers were not involved. If a later notice says government identifiers or financial data were exposed, or you detect identity theft, place freezes and follow the official recovery guidance at IdentityTheft.gov. You can obtain free U.S. credit reports at AnnualCreditReport.com.
- Keep records. Save notices, screenshots, suspicious messages and evidence of unauthorized activity for disputes or identity-theft reports.
What remains unknown
- The confirmed number of affected individuals
- A complete list of affected properties and guests
- Whether the alleged 3.5 million-record figure was accurate
- Whether all data described by the attackers was actually obtained or publicly released
- Whether Omni later offered a broad identity-monitoring program
Those limits matter in 2026: this is a 2024 breach with continuing phishing and account-security implications, not a newly reported 2026 attack. Omni’s current press room does not prominently present a newer public incident update in the material available as of August 18, 2026.
Quick Recap
How to avoid follow-up scams
- Type omnihotels.com into your browser instead of following an email link.
- Check the sender’s full address and beware of look-alike domains.
- Never provide a password, one-time code or full card number to someone who contacted you unexpectedly.
- Do not pay a “verification,” “rebooking” or “account recovery” fee by gift card or cryptocurrency.
- Use the phone numbers published by Omni, not numbers in a suspicious message.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




