CUSTOMER INFORMATION: CYBER INCIDENT
Impacting Guests with a reservation made prior to and including April 24, 2026, with a check-in date after April 25, 2026. If you made a reservation on or after April 25, 2026, you were not impacted.
We regret to inform our guests of a data security incident that may have involved some of your personal information. While our own internal systems were not compromised, we recently learned that there was a compromise involving a third-party hospitality management platform provider we use for managing reservations.
The incident only impacted guests with reservations made prior to and including April 24, 2026, with a check-in date of April 25, 2026, or later at the following Bellstar Resorts:
· Grande Rockies Resort
· Bellstar Suites at Solara Resort
· The Royal Kelowna
· Kicking Horse Lodging
· Glacier Mountaineer Lodge
-
On April 24, 2026, the platform provider notified us that an unauthorized party had gained access to their environment on April 24, 2026. They further confirmed that the unauthorized access was eradicated from their environment on the same date, and there has been no further unauthorized access.
As soon as we became aware of this incident, we launched an investigation with the support of the platform provider and an external cybersecurity expert to understand the scope of the incident and determine if any personal information was affected.
We also immediately sent out a notice to all guests to be wary of unauthorized correspondence impersonating Bellstar properties, and advising guests to not click any links, not provide any personal information, and to delete the message.
-
Our investigation determined that the data accessed by the unauthorized individual may have involved your personal information including either or some combination of your:
Name
Email address
Phone number
Reservation number and check in and check out date of your stay at one of our resorts
In some cases, country and city of residence and gender
We have been able to confirm that full credit card numbers and CVV codes were not compromised in this incident.
At this time, we have no information indicating that the threat actor specifically targeted your personal information. Nonetheless, we are proceeding on the basis that the threat actor viewed your information and recommend you do likewise.
-
Impacted customers whose email addresses were on file received an email from TransUnion on behalf of Bellstar.
If you have not received an email but have concerns that your information was impacted please contact the Call Centre number below.
-
We have made changes to our security procedures to decrease the chance of a similar occurrence in the future.
-
Be wary of any Phishing Emails, WhatsApp Messages or Text Messages designed to trick you into sharing your email address and password, credit card information or infect your device with malware and viruses. This includes potential emails and correspondence from scammers pretending to work for Bellstar Resorts. DO NOT click any links in these e‑mails, respond to any messages, or open any attachments until you confirm the authenticity of any correspondence by verifying the identity of the sender (by phone and not email) and checking the sender’s email address / phone number. If you are unsure, please call and confirm with the member of our staff that they did in fact send the correspondence.
While no financial information was involved in this breach, we recommend that you monitor your accounts: Regularly review your bank, credit card, and financial statements for any unusual or unauthorized activity.
Our customers’ safety and trust is something we value of the highest importance. Bellstar remains committed to ensuring that personal data is always kept secure and are taking every possible action to further improve our security measures to prevent this kind of incident in the future. We regret that this incident has happened and sincerely apologize for any inconvenience.
If you have any questions or concerns regarding this incident, please contact our dedicated assistance team toll‑free at 1‑833‑787‑9274, Monday through Friday, from 8 a.m. to 8 p.m. EST.
