Bed and Breakfast Planner Data Breach: 40,697 Canadian Hospitality Records Exposed
Bed and Breakfast Planner Data Breach: 40,697 Canadian Hospitality Records Exposed
Bed and Breakfast Planner was a Canadian online platform serving the bed-and-breakfast hospitality sector -- a directory and planning resource connecting travellers with independent B&B accommodations across Canada and beyond. The platform built a substantial user base of both guests and hosts over its years of operation. On November 23, 2017, the platform's database of 40,697 user records was extracted and leaked. The breach exposed credentials stored in plaintext -- meaning every password in the database was immediately readable to anyone who accessed it, with zero cracking required.
Bed and Breakfast Planner (November 2017): Breach Summary
- Records Exposed: 40,697
- Data Types: Email addresses, passwords
- Breach Type: Database breach
- Password Type: Plaintext -- no hashing or encryption applied. Passwords are directly readable in the exposed database.
- Country: Canada
- Date Leaked: November 23, 2017
Hospitality Platform Data and the Traveler Identity Risk
Bed-and-breakfast listing platforms occupy a specific niche in the travel sector: they attract users who are actively planning trips, managing accomodation bookings, and in the case of hosts, operating small businesses. This creates a user base with two distinct risk profiles. Guest accounts expose personal travel patterns, home addresses (often provided during booking), and email-password combinations likely reused on airlines, rental car services, and financial platforms used for travel. Host accounts are more sensitive still: a compromised B&B host account can expose banking information, tax details, and the operational data of a small hospitality buisness. For both groups, the November 2017 plaintext breach created immediate credential reuse risk.
2017: Before the Major Breach Waves
The Bed and Breakfast Planner breach predates the massive August 2018 leak clusters by nearly a year -- a reminder that credential exposure is not a recent phenomenon and that older breaches continue to circulate in attacker databases long after their initial disclosure. Credentials exposed in late 2017 that have never been changed remain as actionable today as they were the day they leaked. For travlers who registered on the platform years ago and have since moved on, the risk doesn't expire: the plaintext password is still in the database, still readable, and still available to whoever accesses the breach data.
Canadian Credential Exposure in Context
Canadian internet users are frequently underrepresented in breach monitoring services that focus primarily on American or European platforms. Bed and Breakfast Planner's Canadian origin means its users may have less awareness of the breach than they would if a major American platform were involved -- and may not have taken protective action in the years since. The hospitality sector's reliance on trust-based relationships between hosts and guests makes credential theft particularly disruptive: an attacker with access to a host's account can manipulate listings, intercept guest communications, or redirect payments.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records, including Canadian hospitality platform breaches from 2017 and beyond. If you planned a B&B stay or hosted guests through this platform, your plaintext password was immediately readable when the database was accessed. Run a free scan now and find out exactly what of your data is out there.
Breach Breakdown
40,697 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds