// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

Guesty

DISCLOSED 2026-08-18 · SUPPLY CHAIN · 4,000,000 RECORDS EXPOSED · RANSOMWARE

Credentials were exposed in plain text in CI pipeline logs, likely granting attackers administrative cloud access. The Vect ransomware group claims to have stolen internal projects and 4 million emails from Guesty. The breach involved ransomware and data theft.

The record

What we know

Disclosed
2026-08-18
Attack vector
Supply Chain
Records exposed
4,000,000
Data classes exposed
internal projectsemails
RANSOMWARE
Sources

Cited reporting

Similar vector · recent

Other supply chain breaches on file

This page is the permanent ColdRecon entry for the Guesty disclosure. It updates if new public reporting emerges. All tracked breaches →

Guesty just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →