Skip to content
All industries
Hospitality & Real Estate

Protect guest data, loyalty systems and property records across every site.

Hotels aggregate PII, payment cards, passports and loyalty points across thousands of distributed properties, while real-estate firms hold client, tenant and transaction data in CRM and SaaS estates that legacy SIEMs never watch. Both are target-rich and both are being hit: ransomware on the property side, SaaS extortion on the deal side. Blacklight gives you centralised visibility across every PMS, POS and CRM, without per-site deployment pain.

Incidents and active campaigns in your sector

The pattern is published.

Notable incidents and active campaigns in your sector. The attacker techniques are documented. The regulator timelines are running. Blacklight contains the same patterns autonomously, before the disclosure window opens.

  • Omni Hotels & Resorts
    Daixin ransomware, customer data stolen, March 2024
    Reservation and POS impact
  • Marcus & Millichap
    Salesforce-centric extortion, 30M+ records threatened, April 2026
    Client and transaction data
  • Hotel sector RAT campaign
    Persistent access via ClickFix
    Multi-chain exposure
Case in point

Omni Hotels & Resorts, March 2024: IT system outage, reservation and POS impact

Hotels aggregate the most attractive dataset in consumer retail. Payment cards, passports, loyalty points, itineraries, room-access patterns: all under one PMS across thousands of properties. The March 2024 Omni Hotels outage, a confirmed Daixin ransomware attack that stole customer data, took down reservations, room-key issuance, and point-of-sale systems for days. Per-property defences mean per-property compromise. Blacklight monitors PMS, POS, and loyalty databases for anomalous access and export patterns across every property from a single console. RAT deployment, ClickFix variants, and persistent-access techniques flagged as they happen, not weeks later in forensics. Containment per-property without central-office intervention. PCI DSS 4.0 and GDPR evidence auto-bundled per region.

The Blacklight difference
  • Correlated against live threat intel in seconds, not hours.
  • Contained autonomously, before the human analyst arrives.
  • Regulator-ready evidence, bundled and pre-drafted.
What Blacklight would do

Four moves,
on autopilot.

Every action is logged, explained, and reversible. The analyst always has the last word, but they get the case ready-made.

  • Monitor PMS, POS, and loyalty databases for anomalous access and export patterns
  • Baseline CRM and SaaS activity so bulk exports of client, tenant and transaction records are caught before they leave
  • Detect RAT deployment and persistent access techniques including ClickFix variants
  • Autonomous containment per-property without central-office intervention
  • PCI DSS 4.0 and GDPR-ready evidence, pre-bundled per region
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.