Company Details
hyatt
85,240
1,537,391
7211
hyatt.com
0
HYA_2728151
In-progress

Hyatt Company CyberSecurity Posture
hyatt.comHyatt is guided by its purpose: to care for people so they can be their best. Hyatt’s portfolio includes 1,000+ hotel and all-inclusive properties in over 75 countries across 6 continents. Hyatt’s offerings include brands in the Timeless Collection, including Park Hyatt®, Grand Hyatt®, Hyatt Regency®, Hyatt®, Hyatt Residence Club®, Hyatt Place®, Hyatt House®, Hyatt Studios, and UrCove; the Boundless Collection, including Miraval®, Alila®, Andaz®, Thompson Hotels®, Dream® Hotels, Hyatt Centric®, and Caption by Hyatt®, the Independent Collection, including The Unbound Collection by Hyatt®, Destination by Hyatt®, and JdV by Hyatt®, and the Inclusive Collection, including Impression by Secrets, Hyatt Ziva®, Hyatt Zilara®, Zoëtry® Wellness & Spa Resorts, Secrets® Resorts & Spas, Breathless Resorts & Spas®, Dreams® Resorts & Spas, Hyatt Vivid Hotels & Resorts, Alua Hotels & Resorts®, and Sunscape® Resorts & Spas. Subsidiaries of Hyatt operate the World of Hyatt® loyalty program, ALG Vacations®, Unlimited Vacation Club®, Amstar DMC destination management services, and Trisept Solutions® technology services. Visit www.hyatt.com for more. This account provides information about Hyatt Hotels Corporation, its subsidiaries or affiliates and/or hotels operating under a Hyatt-affiliated brand. Terms like “Hyatt,” “we,” “our,” “us,” and similar terms are used for convenience and should not be understood as precise designations of any particular entity. The account name and certain terms like “employees” are used by this site but may not be accurate. Individuals may identify themselves as working or having worked at Hyatt or a Hyatt hotel, but please note that self-identification should not be treated as confirmation of employment, past or present, by Hyatt or any particular entity or hotel. In some cases, an individual may have been employed by an affiliate of Hyatt Hotels Corporation or by an owner or franchisee of a Hyatt-branded hotel.
Company Details
hyatt
85,240
1,537,391
7211
hyatt.com
0
HYA_2728151
In-progress
Between 750 and 799

Hyatt Global Score (TPRM)XXXX

Description: The Washington State Office of the Attorney General reported a data breach involving Hyatt Hotels Corporation on October 12, 2017. The breach occurred between March 18, 2017 and July 2, 2017, potentially affecting 640 Washington residents with unauthorized access to payment card information, including cardholder names, card numbers, expiration dates, and internal verification codes.
Description: The Washington Office of the Attorney General reported a data breach involving Hyatt Hotels Corporation on January 14, 2016. The breach, which involved unauthorized access to payment card data, occurred between August 13, 2015, and December 8, 2015, affecting 15 individuals. The breach was due to malware specifically designed to target payment card data.
Description: Hyatt Hotels chain across the was infected by a malware attack back in January 2016. The attackers designed the malware to exfiltrated payment card information including cardholder names, card numbers, expiration dates, and internal verification code affected payment processing systems. The hotel chain offered one year’s free protection to those affected by the breach,


No incidents recorded for Hyatt in 2025.
No incidents recorded for Hyatt in 2025.
No incidents recorded for Hyatt in 2025.
Hyatt cyber incidents detection timeline including parent company and subsidiaries

Hyatt is guided by its purpose: to care for people so they can be their best. Hyatt’s portfolio includes 1,000+ hotel and all-inclusive properties in over 75 countries across 6 continents. Hyatt’s offerings include brands in the Timeless Collection, including Park Hyatt®, Grand Hyatt®, Hyatt Regency®, Hyatt®, Hyatt Residence Club®, Hyatt Place®, Hyatt House®, Hyatt Studios, and UrCove; the Boundless Collection, including Miraval®, Alila®, Andaz®, Thompson Hotels®, Dream® Hotels, Hyatt Centric®, and Caption by Hyatt®, the Independent Collection, including The Unbound Collection by Hyatt®, Destination by Hyatt®, and JdV by Hyatt®, and the Inclusive Collection, including Impression by Secrets, Hyatt Ziva®, Hyatt Zilara®, Zoëtry® Wellness & Spa Resorts, Secrets® Resorts & Spas, Breathless Resorts & Spas®, Dreams® Resorts & Spas, Hyatt Vivid Hotels & Resorts, Alua Hotels & Resorts®, and Sunscape® Resorts & Spas. Subsidiaries of Hyatt operate the World of Hyatt® loyalty program, ALG Vacations®, Unlimited Vacation Club®, Amstar DMC destination management services, and Trisept Solutions® technology services. Visit www.hyatt.com for more. This account provides information about Hyatt Hotels Corporation, its subsidiaries or affiliates and/or hotels operating under a Hyatt-affiliated brand. Terms like “Hyatt,” “we,” “our,” “us,” and similar terms are used for convenience and should not be understood as precise designations of any particular entity. The account name and certain terms like “employees” are used by this site but may not be accurate. Individuals may identify themselves as working or having worked at Hyatt or a Hyatt hotel, but please note that self-identification should not be treated as confirmation of employment, past or present, by Hyatt or any particular entity or hotel. In some cases, an individual may have been employed by an affiliate of Hyatt Hotels Corporation or by an owner or franchisee of a Hyatt-branded hotel.


Deutsche Hospitality stands for an exceptional portfolio comprising more than 130 hotels in 20 countries on three continents, about 30 hotels are currently under development. Deutsche Hospitality stands for an exceptional portfolio comprising more than 130 hotels in 20 countries on three continents

The resorts and casinos of MGM Resorts International™ are some of the most famous in the world. Our 28 destinations are renowned for their winning combination of quality entertainment, luxurious facilities, and exceptional customer service. We are actively expanding our presence globally, with pot

Ovations Food Services is now Spectra. Spectra is an industry leader in hosting and entertainment, partnering with clients to create memorable experiences for millions of visitors every year. Spectra’s unmatched blend of integrated services delivers incremental value for clients through several pri

IHG Hotels & Resorts [LON:IHG, NYSE:IHG (ADRs)] is a global hospitality company, with a purpose to provide True Hospitality for Good. With a family of 19 hotel brands and IHG One Rewards, one of the world's largest hotel loyalty programmes, IHG has over 6,300 open hotels in more than 100 countries,

Welcome to Meliá Hotels International! From Mallorca to the world, our story is an exciting journey that began more than six decades ago and has led us to become one of the largest hotel chains on the planet and the most sustainable in Europe (S&P Global). With more than 400 hotels across the worl

Jumeirah, a global leader in luxury hospitality and a member of Dubai Holding, operates an exceptional portfolio of 31 properties, including 33 signature F&B restaurants, across the Middle East, Europe, Asia and Africa. In 1999, Jumeirah changed the face of luxury hospitality with the opening of t

Welcome to Hyatt Regency hotels, where connections flow seamlessly whether you’re traveling for business or leisure. With more than 150 hotels in over 30 countries, Hyatt Regency is a welcome place for convention goers, business travelers, and leisure seekers alike. Find yourself surrounded by en

Since inception, Rotana has grown to be the region’s largest hospitality management company, and a brand that is widely recognized and admired. Rotana currently manages a portfolio of over 100 properties throughout the Middle East, Africa, Eastern Europe and Türkiye offering a wide range of servic

SJM Resorts, S.A. ("SJM") is one of the six concessionaires in Macau, authorised by the Government of the Macau Special Administrative Region to operate casinos and gaming areas. SJM is also the only casino gaming concessionaire with its roots in Macau. SJM owns and operates the Grand Lisboa Palace
.png)
Christian Hyatt is CEO and co-founder of cybersecurity consulting firm risk3sixty. The company's health care benefits and culture that...
The 18th edition of cOcOn, the annual international cybersecurity conference organised by the Kerala Police, was held at the Grand Hyatt,...
Pinarayi stressed the need for electronic governance systems to prepare for growing cyber threats as public services become increasingly...
COCON 2025 cybersecurity conference by Kerala Police & ISRA features workshops, keynotes, and strategic responses to cyber threats.
Kerala Police's flagship event brings global experts, hands-on hacking villages, and cutting-edge insights to secure the cyber future.
World of Hyatt, the award-winning loyalty program from Hyatt, is announcing a new regional collaboration with HYROX Asia Pacific—one of the...
Join c0c0n 2025 in Kochi, Oct 7-11, Asia`s leading cybersecurity & hacking conference. Connect, collaborate, & contribute to securing the...
New Delhi [India], September 22: CyberMindr Joins the ETCISO Annual Conclave 2025 as a supporting partner. Held from September 18 to 21 at...
Hyatt Hotels Corporation (NYSE: H), Kiraku, Inc. (“Kiraku”). and Takenaka Corporation announced today the final close of Atona Impact Fund,...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Hyatt is http://www.hyatt.com.
According to Rankiteo, Hyatt’s AI-generated cybersecurity score is 770, reflecting their Fair security posture.
According to Rankiteo, Hyatt currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Hyatt is not certified under SOC 2 Type 1.
According to Rankiteo, Hyatt does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Hyatt is not listed as GDPR compliant.
According to Rankiteo, Hyatt does not currently maintain PCI DSS compliance.
According to Rankiteo, Hyatt is not compliant with HIPAA regulations.
According to Rankiteo,Hyatt is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Hyatt operates primarily in the Hospitality industry.
Hyatt employs approximately 85,240 people worldwide.
Hyatt presently has no subsidiaries across any sectors.
Hyatt’s official LinkedIn profile has approximately 1,537,391 followers.
Hyatt is classified under the NAICS code 7211, which corresponds to Traveler Accommodation.
No, Hyatt does not have a profile on Crunchbase.
Yes, Hyatt maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/hyatt.
As of November 27, 2025, Rankiteo reports that Hyatt has experienced 3 cybersecurity incidents.
Hyatt has an estimated 13,641 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach and Ransomware.
Title: Hyatt Hotels Malware Attack
Description: Hyatt Hotels chain across the was infected by a malware attack back in January 2016. The attackers designed the malware to exfiltrated payment card information including cardholder names, card numbers, expiration dates, and internal verification code affected payment processing systems.
Date Detected: 2016-01-01
Type: Malware Attack
Attack Vector: Malware
Motivation: Financial Gain
Title: Hyatt Hotels Corporation Data Breach
Description: The Washington State Office of the Attorney General reported a data breach involving Hyatt Hotels Corporation on October 12, 2017. The breach occurred between March 18, 2017 and July 2, 2017, potentially affecting 640 Washington residents with unauthorized access to payment card information, including cardholder names, card numbers, expiration dates, and internal verification codes.
Date Detected: 2017-10-12
Date Publicly Disclosed: 2017-10-12
Type: Data Breach
Title: Hyatt Hotels Corporation Data Breach
Description: The Washington Office of the Attorney General reported a data breach involving Hyatt Hotels Corporation on January 14, 2016. The breach, which involved unauthorized access to payment card data, occurred between August 13, 2015, and December 8, 2015, affecting 15 individuals. The breach was due to malware specifically designed to target payment card data.
Date Detected: 2016-01-14
Date Publicly Disclosed: 2016-01-14
Type: Data Breach
Attack Vector: Malware
Vulnerability Exploited: Unauthorized access to payment card data
Motivation: Financial Gain
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Cardholder names, Card numbers, Expiration dates, Internal verification code
Systems Affected: Payment Processing Systems
Payment Information Risk: True

Data Compromised: Cardholder names, Card numbers, Expiration dates, Internal verification codes
Payment Information Risk: True

Data Compromised: Payment card data
Payment Information Risk: High
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Payment Card Information, , Payment Card Information, and Payment card data.

Entity Name: Hyatt Hotels
Entity Type: Hotel Chain
Industry: Hospitality

Entity Name: Hyatt Hotels Corporation
Entity Type: Hospitality
Industry: Hospitality
Location: Washington
Customers Affected: 640

Entity Name: Hyatt Hotels Corporation
Entity Type: Corporation
Industry: Hospitality
Customers Affected: 15

Type of Data Compromised: Payment card information
Sensitivity of Data: High

Type of Data Compromised: Payment card information
Number of Records Exposed: 640
Sensitivity of Data: High

Type of Data Compromised: Payment card data
Number of Records Exposed: 15
Sensitivity of Data: High

Source: Washington State Office of the Attorney General
Date Accessed: 2017-10-12

Source: Washington Office of the Attorney General
Date Accessed: 2016-01-14
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Washington State Office of the Attorney GeneralDate Accessed: 2017-10-12, and Source: Washington Office of the Attorney GeneralDate Accessed: 2016-01-14.

Customer Advisories: The hotel chain offered one year’s free protection to those affected by the breach
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was The hotel chain offered one year’s free protection to those affected by the breach.
Most Recent Incident Detected: The most recent incident detected was on 2016-01-01.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2016-01-14.
Most Significant Data Compromised: The most significant data compromised in an incident were Cardholder Names, Card Numbers, Expiration Dates, Internal Verification Code, , cardholder names, card numbers, expiration dates, internal verification codes, and Payment card data.
Most Significant System Affected: The most significant system affected in an incident was Payment Processing Systems.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were expiration dates, internal verification codes, Card Numbers, Cardholder Names, Payment card data, card numbers, Internal Verification Code, Expiration Dates and cardholder names.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 655.0.
Most Recent Source: The most recent source of information about an incident are Washington Office of the Attorney General and Washington State Office of the Attorney General.
Most Recent Customer Advisory: The most recent customer advisory issued was an The hotel chain offered one year’s free protection to those affected by the breach.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.