Hacker Claims 4.5 Million Records Linked to Italian Hotel Software Firm WuBook Leaked

Last updated: September 28, 2026 Reading time: 4 minutes
Disclosure
Share
Hacker Claims 4.5 Million WuBook User Records have Been Leaked
  • An underground forum user says they leaked 4.5 million names and IDs tied to WuBook, an Italian hotel software company.
  • Nobody has confirmed it. Searches found no WuBook statement and no independent check of the data.
  • Even a names-only list can help scammers pose as hotels, guests, or booking partners.

A hacker on an underground forum says they have published about 4.5 million records linked to WuBook. The company makes software for hotels. The post says the data covers 4,511,221 unique people and pairs user IDs with first and last names. It comes as one 362 MB JSON file with several download links.

None of this has been validated yet. There’s currently no outside verification or public report from WuBook confirming this claim.

What the Poster Claims

The claim appeared in a social media post about the alleged leak. It describes a narrow set of data. The post does not mention emails, phone numbers, passwords, payment cards, or ID scans. The poster reportedly called the data limited.

That matters. A list of names and IDs is far less dangerous than a full guest profile. Still, 4.5 million is a big number. It is unclear whether these people are guests, hotel staff, or account holders. It is also unclear how old the data is.

Why WuBook Makes for an Attractive Target

WuBook is a provider of hotel management solutions. Its website features property management systems, a booking engine, and a channel manager. A channel manager ensures synchronization of room inventories across multiple booking platforms. WuBook claims that over 22,000 establishments around the world use its software, and more than 500 partners have integrated its solutions.

This wide adoption explains the threat actor’s interest. A company developing hotel management software sits between hotels, guests, and booking websites. Information flowing through this pipeline could involve multiple businesses at once.

WuBook also mentions its security capabilities. In a blog post from their official website, WuBook states that its Zak system is PCI-DSS certified (a payment card industry standard), and the certificate covers the entire server perimeter. These are the exact words of the company and do not provide any evidence of the leak.

Why It’s Fair to Doubt this Claim

Most forum claims turn out to be inaccurate. Reports on a separate case in 2025 shows that criminals often provide claims which are exaggerated, embellished, or completely fabricated. A huge dump does not imply that WuBook’s databases have been compromised. The actor may have obtained the data from partners, prior leaks, or web scraping of the public pages.

Several measures could easily solve most of these concerns. For instance, the researchers can examine a random selection of the data with respect to the existing accounts. The researchers can cross-check the database against other leaks as well. In addition, WuBook can verify its logs regarding the claims made.

A Recent Italian Case

Italian hotels have already suffered this kind of attack. In August 2025, Italy’s digital agency AGID said a criminal’s claims about stolen hotel guest IDs were genuine, and that at least ten hotels were affected. Italy’s data protection authority urged hotels that had not yet reported the incident to do so without delay.

There’s no public link between that case and the WuBook claim. Italy has also featured in other ransomware investigations, including the case covered in Armenian Ryuk ransomware hacker sentenced to 2 years in US prison. But it shows that Italian hotels are a real target, and that regulators there act fast.

Risks this Leak Could Pose

If this listing is valid, the immediate damage will likely not be extensive. Attackers can’t use just names and identifiers to clean out a bank account. What is dangerous is what the criminals might do next with that information.

Scammers could use authentic names to craft realistic phishing emails. For example, an email sent to a receptionist may ask about changing a reservation for a particular person by name. An email claiming to be from an accommodation partner will be trusted based on the name and prompt clicking or credential exchange.

Malicious actors can combine information from different sources. Putting together names from this list, plus an email from another data breach, can give them much more info to work with.

What’s Next for Hotels and Guests?

Hotel staff should slow down on unexpected booking changes, payment requests, and login prompts. Confirm by calling the guest or partner at a number you already have. Turn on two-step login for every hotel software and booking site account. Change any password you reuse.

Guests should be wary of messages about a stay they don’t remember. Don’t click the links. Go to the hotel’s or booking site’s official page instead.

Three things will settle this. One is a statement from WuBook. Another is checks by independent researchers. The third is any notice to regulators. WuBook’s own blog notes that European privacy rules require companies to inform users when they notice a breach of their databases.

For now, treat the leak as unproven. It may be old, recycled, or fake. It may also be real. Either way, the smart move is caution with any message that uses a name you know.

Share this article

About the Author

Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.

More from Farwa Sajjad

Related Posts