Travelodge Room Access Failures: Pattern of Breaches Triggers Independent Security Review

A woman staying at a London Travelodge to escape a domestic abuser was physically assaulted in October 2025 after reception staff gave her abuser a room key and directed him to her room, according to her account to the BBC (The Guardian).
The man gained access by approaching reception and claiming his girlfriend was upstairs having a seizure, then asking for her room and floor number. Staff handed him a key and showed him the way. According to the woman's account to the BBC, the attacker kicked the hotel room door "off its hinges," assaulted her, and attempted to grab her phone (BBC News). After the attack, the woman was offered another room in the same hotel (The Guardian).
Travelodge apologised for its handling of the incident and acknowledged that its room access security policies at the time were not correctly followed. The company stated that such incidents are "very rare" and that customer safety is a priority. It has commissioned an independent review of its room access security policies and escalation procedures, led by barrister Paul Greaney KC (The Guardian). Chief executive Jo Boydell said the safety and security of customers is "extremely important" and that everyone should be safe and feel safe in the hotels (BBC News). Travelodge also said an investigation found its updated room access security policies in place at the time were not correctly followed, and that it retrained the hotel team on room security and check-in procedures (BBC News).
The London case is not isolated. In 2022, a man named Kyran Smith lied to staff at a Travelodge in Maidenhead, claiming to be the boyfriend of a woman staying there. Staff did not verify with the woman before handing over a key card to her room. Smith then sexually assaulted her. He was sentenced in February 2026 to more than seven years in prison. The victim was offered a £30 refund following the assault, which she described as "insulting" (The Guardian; BBC News). The victim sent an email to Travelodge's chief executive in 2023 about the incident. Boydell subsequently offered to meet her and apologised (BBC News; BBC News).
Following the BBC's coverage of the Maidenhead case, other guests came forward with their own accounts. A woman named Jo, from Leeds, said she woke in July 2025 to an unknown man standing at the end of her bed in a Travelodge room and screamed for help. A friend sharing the room heard the man say, "I'm sorry, they gave me this key" (BBC News). Separately, Andy Smith, a musician who stays in dozens of Travelodge hotels a year, said he had recently been given keys to other people's rooms, and on one occasion found a man asleep in his room in a state of undress. About 18 months before that, another man had gained access to Smith's Travelodge room by telling reception he was checking in under a common name such as "Mr Smith." Travelodge responded to those incidents by saying any case of an unauthorised person entering a guest's room is "a significant cause for concern" and that "these incidents should not have happened" (BBC News).
MPs had previously written to Travelodge asking it to review its policies around women's safety (The Guardian). Travelodge is also carrying out a full review following two women telling the BBC that unknown people entered their rooms while staying at Travelodge hotels (BBC News).
The pattern across these cases shares a consistent failure mode: front desk staff released room keys to individuals who were not verified as registered guests or authorised by the actual guest, without contacting the guest in the room first. In the London case, the social engineering tactic was a fabricated medical emergency. In the Maidenhead case, it was a claim of a romantic relationship. In Andy Smith's account, it was the exploitation of a common surname. Each relied on staff discretion rather than a hard protocol, and each bypassed whatever written policies Travelodge says were in place.
The broader context here is one of institutional lag between stated policy and operational reality. Travelodge maintains that its room access security policies were not correctly followed in these instances, which raises questions about whether the policies themselves are sufficiently robust against social engineering, or whether training and enforcement mechanisms are adequate to ensure compliance at the front desk level under real-world pressure. The independent review led by Paul Greaney KC may address both dimensions, but its terms of reference and expected publication date have not been detailed in public reporting.
For hospitality security professionals, the cases underscore a familiar vulnerability: key card systems are only as strong as the human authentication process governing their distribution. When a receptionist can override room privacy based on an unverified verbal claim, the technical security of the lock is irrelevant. The fact that these incidents span at least three years and multiple locations suggests a systemic rather than localised issue, and the adequacy of Travelodge's response will likely be measured against whether similar breaches continue after the review and retraining are completed.


