Skip to content
Back to Blog
high severity September 17, 2026 · 3 min read Unverified claim — what this is

fchhotels.com Listed by Settra Ransomware Group

If you are a customer of fchhotels.com, here’s what is being claimed, and what it would mean for you.

THE FIRST CALL The company that manages your hotel and calls itself "First Call Hospitality" forgot ...

— from Settra’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
fchhotels.com Listed by Settra Ransomware Group

Your account with First Call Hospitality may now be part of an extortion attempt. The ransomware group Settra has listed fchhotels.com on its leak site, claiming it obtained data during an incident dated August 31, 2026. The company has not publicly confirmed the claim as of this writing.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

This means that if the claim is accurate, information tied to your hotel booking account, loyalty profile, or reservation history could be in the attackers’ hands. Because no categories of data are named in the filing and the number of affected individuals is not stated, you cannot know from this record alone whether your specific records are involved. The only way to be certain is through direct notification from First Call Hospitality itself, typically sent by post to your last known address.

If the Group’s Claim Is True, What Changes for You

The filing does not list any exposed fields, so the record is silent on whether passwords, payment details, contact information or anything else was taken. A password field is mentioned in the associated credential exposure note, but the storage scheme used by the company is not disclosed. This leaves open the possibility that any stored password could be cracked and used elsewhere.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

Because no permanent government or biographic identifiers such as Social Security numbers or passport numbers appear in the record, the long-term identity theft risk that often accompanies healthcare or financial breaches does not apply here. That is genuinely good news. The main ongoing concern is account-level abuse: someone could attempt to use stolen login details on your First Call Hospitality account or on other sites where you reused the same password.

What a Leak-Site Listing Actually Establishes

Leak-site postings by ransomware groups are produced under pressure. The group’s business model depends on convincing the target to pay to prevent publication. As a result, many listings contain recycled data from older incidents, exaggerated claims, or sometimes entirely fabricated entries designed to create urgency.

In the hospitality sector this tactic has become common. Settra and similar crews frequently add hotel management and resort operators to their sites with minimal proof. A listing alone does not constitute confirmation that a breach occurred, that data was allegedly stolen, or that any customer records left the company’s environment. Real confirmation would require an admission by First Call Hospitality, a regulatory filing that clearly describes a compromise, or forensic evidence released by a credible third party. None of those exist here. The page you are reading reflects an unverified accusation, not an established fact.

The Pattern Seen Across Hospitality Targets

Ransomware groups have repeatedly used leak sites to pressure companies in the hotel and restaurant sector. They know these organisations rely on reputation and rapid guest turnover, making even the threat of exposure costly. Many such listings later prove to be overstated or drawn from breaches that happened months or years earlier.

For you as a customer, this pattern means you will likely see more of these claims in the coming years. The useful takeaway is simple: treat every reused password as a liability. A single password that works on your hotel loyalty account, your email, and your credit card portal turns one uncertain incident into access across your digital life. Changing passwords after every reported incident is impractical, but using unique, strong passwords for hospitality and travel accounts reduces the blast radius if any one of them is compromised.

Concrete Steps You Can Take Today

  • Change your First Call Hospitality password immediately to one you have never used anywhere else. This limits damage if credentials were taken and the storage was weak.
  • Enable two-factor authentication on the fchhotels.com account and every other travel or loyalty account. This blocks login attempts even if the password is known.
  • Audit password reuse across your accounts. Use a password manager to generate and store unique credentials for every hotel, airline, and booking site you use.
  • Watch for any letter or email from First Call Hospitality. If you have moved since August 31, 2026, contact the company directly using the customer service number on their website to confirm whether your records were involved. Absence of a letter usually indicates you were not in the affected group, but addresses can change.
  • Monitor your credit card statements and loyalty accounts for unexpected bookings or charges over the next several months.

GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, with identity-chain mapping and remediation handled by specialists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
fchhotels.com is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High the filing does not enumerate what was exposed
Disclosed September 17, 2026
Last reviewed September 17, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email