fchhotels.com Listed by Settra Ransomware Group
If you are a customer of fchhotels.com, here’s what is being claimed, and what it would mean for you.
THE FIRST CALL The company that manages your hotel and calls itself "First Call Hospitality" forgot ...
— from Settra’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
fchhotels.com customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
Your account with First Call Hospitality may now be part of an extortion attempt. The ransomware group Settra has listed fchhotels.com on its leak site, claiming it obtained data during an incident dated August 31, 2026. The company has not publicly confirmed the claim as of this writing.
This means that if the claim is accurate, information tied to your hotel booking account, loyalty profile, or reservation history could be in the attackers’ hands. Because no categories of data are named in the filing and the number of affected individuals is not stated, you cannot know from this record alone whether your specific records are involved. The only way to be certain is through direct notification from First Call Hospitality itself, typically sent by post to your last known address.
If the Group’s Claim Is True, What Changes for You
The filing does not list any exposed fields, so the record is silent on whether passwords, payment details, contact information or anything else was taken. A password field is mentioned in the associated credential exposure note, but the storage scheme used by the company is not disclosed. This leaves open the possibility that any stored password could be cracked and used elsewhere.
- Every indexed leak tied to your address — all of them, named and dated
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Because no permanent government or biographic identifiers such as Social Security numbers or passport numbers appear in the record, the long-term identity theft risk that often accompanies healthcare or financial breaches does not apply here. That is genuinely good news. The main ongoing concern is account-level abuse: someone could attempt to use stolen login details on your First Call Hospitality account or on other sites where you reused the same password.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
What a Leak-Site Listing Actually Establishes
Leak-site postings by ransomware groups are produced under pressure. The group’s business model depends on convincing the target to pay to prevent publication. As a result, many listings contain recycled data from older incidents, exaggerated claims, or sometimes entirely fabricated entries designed to create urgency.
In the hospitality sector this tactic has become common. Settra and similar crews frequently add hotel management and resort operators to their sites with minimal proof. A listing alone does not constitute confirmation that a breach occurred, that data was allegedly stolen, or that any customer records left the company’s environment. Real confirmation would require an admission by First Call Hospitality, a regulatory filing that clearly describes a compromise, or forensic evidence released by a credible third party. None of those exist here. The page you are reading reflects an unverified accusation, not an established fact.
The Pattern Seen Across Hospitality Targets
Ransomware groups have repeatedly used leak sites to pressure companies in the hotel and restaurant sector. They know these organisations rely on reputation and rapid guest turnover, making even the threat of exposure costly. Many such listings later prove to be overstated or drawn from breaches that happened months or years earlier.
For you as a customer, this pattern means you will likely see more of these claims in the coming years. The useful takeaway is simple: treat every reused password as a liability. A single password that works on your hotel loyalty account, your email, and your credit card portal turns one uncertain incident into access across your digital life. Changing passwords after every reported incident is impractical, but using unique, strong passwords for hospitality and travel accounts reduces the blast radius if any one of them is compromised.
Concrete Steps You Can Take Today
- Change your First Call Hospitality password immediately to one you have never used anywhere else. This limits damage if credentials were taken and the storage was weak.
- Enable two-factor authentication on the fchhotels.com account and every other travel or loyalty account. This blocks login attempts even if the password is known.
- Audit password reuse across your accounts. Use a password manager to generate and store unique credentials for every hotel, airline, and booking site you use.
- Watch for any letter or email from First Call Hospitality. If you have moved since August 31, 2026, contact the company directly using the customer service number on their website to confirm whether your records were involved. Absence of a letter usually indicates you were not in the affected group, but addresses can change.
- Monitor your credit card statements and loyalty accounts for unexpected bookings or charges over the next several months.
GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, with identity-chain mapping and remediation handled by specialists.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
naturesplus.com Listed by Settra Ransomware Group
Documents: Natural Organics, Inc. / NaturesPlus PROLOGUE CEO Jim Gibbons, between 2015 and 2019, pur…
sym.com.mx Listed by Settra Ransomware Group
SÁNCHEZ Y MARTÍN, S.A. DE C.V.: Critical Incidents and Active Infrastructure PROLOGUE Inside: RFC SM…
budgetms.com Listed by Settra Ransomware Group
CLEAN WORK The company that cleans other people's buildings and supplies janitorial products left ev…