INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Parnassus Hotel Rewards member info leaked, reservation data compromised
| 2026-10-01 16:35 HIGH LOW DATA BREACH
Executive Summary
AI-generated
On September 24th to 25th, an unauthorized external third party accessed and disclosed some member information through illegal means of Parnas Hotel & Resort's integrated membership program 'Parnas Rewards', resulting in the disclosure of individual member information including eight items such as member ID, membership number, name, gender, birth year, reservation information, mobile phone number, and email address. The leaked data affected approximately 360,000 members with the disclosed information not yet confirmed to be resident registration numbers, credit card information, payment information, and passwords being unaffected by the incident. Additional measures were taken including monitoring related systems, reporting and cooperating with relevant institutions, and monitoring phishing messages and related circumstances after the unauthorized access was detected, while a precise investigation and security monitoring are planned with external expert institutions.
Technical Mitigations AI-generated
• Block phishing messages and related circumstances.
• Monitor phishing messages and report suspicious activity to the Korea Internet & Security Agency (KISA).
• Use official Kakao Alrim Talk and official emails for reservation-related announcements.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
hospitalityhospitality
Incident Timeline
September 24th to 25th
An unauthorized external third party accessed and disclosed Parnassus Hotel Rewards member information through illegal means between September 24th and 25th.
Click on any entity below to view its context and source!
tactic
Data Breach
The hotel has released a statement on 'Notification of Data Breach and Apology' stating that since September 24th to 25th, an unauthorized external third party accessed and disclosed some member information through illegal means.
September 29th
Threat actors used stolen Parnassus Hotel Rewards member information to send fake payment alerts, which were reported by the hotel on September 29th.
Click on any entity below to view its context and source!
organisation
Parnas Hotel & Resort
On September 29th, Parnas Hotel & Resort reported the incident to the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA).
organisation
the Personal Information Protection Commission
On September 29th, Parnas Hotel & Resort reported the incident to the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA).
organisation
the Korea Internet & Security Agency
On September 29th, Parnas Hotel & Resort reported the incident to the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA).
organisation
KISA
On September 29th, Parnas Hotel & Resort reported the incident to the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA).
2026/10/01
Parnas Hotel & Resort's integrated membership program 'Parnas Rewards' experienced a data breach incident resulting in the disclosure of individual member information.
Click on any entity below to view its context and source!
organisation
Parnas Hotel & Resort's
Parnas Hotel & Resort's integrated membership program 'Parnas Rewards' experienced a data breach incident, resulting in the disclosure of individual member information.
organisation
Parnas Hotel
Parnas Hotel stated in an official announcement that so far, as of the current results, resident registration numbers, credit card information, payment information, and passwords were not affected by the incident.
organisation
WhatsApp
They warned that links to reservation confirmation and payment requests received through unofficial channels, such as WhatsApp, should not be clicked and should be deleted.
organisation
Paranas Hotel & Resort
To confirm reservations, customers can use the official website of Paranas Hotel & Resort or the official reservation desk of the hotel where they made the reservation.
organisation
FAQ
The company stated in its FAQ that customers who want to cancel their reservations due to the incident can cancel without additional cancellation fees on its official website.
data_breach
360,000 members
Parnas Rewards has approximately 360,000 members, but the actual number of members whose information was disclosed and the corresponding ratio have not been confirmed.
Tactical Metrics
Metrics
data_breach
360,000
Members
Click for context!
Parnas Rewards has approximately 360,000 members, but the actual number of members whose information was disclosed and the corresponding ratio have not been confirmed.
Intelligence Sources
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
9x
organisation
Identified Entity
Parnas Hotel & Resort's
entity
2x
tactic
Cyber Operation Type
Data Breach
tactic
2x
timeline
Temporal Reference
September 24th to 25th
date
Contextual Telemetry
Context Block
2 METRICS
industry
Targeted Sector
Hospitality
sector
data breach
Members
360,000
members
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.