Data breach leaks sensitive, private, and financial data of millions of customers from Booking.com, Expedia, Hotels.com, and others who use Prestige Software
The list of online booking sites affected by the breach includes some of the top industry giants including Booking.com.
Context & Ripple Effects
The Prestige Software breach is the latest entry in a pattern the related coverage has tracked for years: hospitality data leaking not through the brands customers trust, but through the plumbing behind them. Expedia's own Orbitz hack exposed roughly 880,000 payment cards in 2018, and Marriott's Starwood breach compromised 500M guest records dating back to 2014 — in both cases the attacker reached data through systems the front-facing brand didn't fully control.
What distinguishes this incident is that Prestige Software sits even further downstream: a vendor serving Booking.com, Expedia, Hotels.com, and other booking sites simultaneously, meaning one compromise fans out across competitors at once. It also echoes the quieter finding from Symantec's review of 1,500 hotels across 54 countries, where ~67% of hotel websites were inadvertently leaking guest booking details to third-party ad and analytics services — the industry's data exposure problem is structural, not incidental.
First-order effects
- Booking.com, Expedia, and Hotels.com customers whose reservations ran through Prestige Software now have sensitive, private, and financial data exposed, while the brands themselves must answer for a vendor breach they did not directly suffer.
- Prestige Software faces immediate reputational and contractual jeopardy as a channel manager whose core product is trusted handling of booking and payment data.
Second-order effects
- Booking platforms and hotel chains will harden vendor due diligence — audits, contractual liability, and security requirements for channel managers and reservation middleware — shifting compliance costs onto the third-party software tier.
- The incident hands ammunition to competitors and aggregators marketing direct-booking or first-party-data positioning, since 'your data touches fewer hands' becomes a sellable claim.
Third-order effects
- If the pattern holds — Orbitz, Starwood, and now Prestige Software — the hospitality industry's real security perimeter is its vendor ecosystem, pushing regulators and insurers to treat third-party reservation software as critical infrastructure rather than a brand's IT footnote.
- Consolidation pressure builds on the middleware tier: smaller channel managers that cannot absorb breach liability will lose customers to larger vendors, concentrating booking data in fewer, bigger targets.
The trend: Travel's data-security failures are migrating from the brands customers know to the third-party software layer beneath them, making vendor ecosystems the industry's systemic weak point.