Community
The Destination Hotels & Resorts cyber security breach is not the first report of credit card details being stolen from hotel databases.
Hotels are a fantastic target for identity thieves. Hotel databases don't just hold credit card numbers and billing addresses (which are held for weeks in advance of a stay and for weeks afterwards to secure incidentals, complicating PCI data retention requirements), but for many customers the hotel also has their home address, driver licence number, airline memberships, arrival flight details, and even their passport number. It's a complete cornucopia for criminals.
And the most dangerous, most difficult to control threat vector in the hotel industry won't be war-driving or SQL injection attacks or any of the other high tech hacking tools used by organised crime. It will be the inside job. Thousands of itinerant hotel workers in every corner of the world have the opportunity to access office systems after hours, and simply download the contents of central databases to a thumb drive.
Has anyone asked the obvious question: Was the hotel PCI compliant? How feasible is PCI-DSS for hotel chains with their horribly decentralised computer systems and untold interconnections with airlines, travel agencies and the like? And as I've discussed previously, what difference would PCI compliance make anyway?
The vulnerability of hotel databases to identity thieves has clear implications for national security. I trust that counter terrorism agencies are working on this problem? Not only do these databases hold credit card, driver licence and passport numbers, but they also tell of the forward travel plans for thousands of VIPs worldwide.
We should expect that organised criminals and terrorist organisations are tapped into hotel databases as we speak, and are mining them systematically.
Stephen Wilson, Lockstep, Australia.
This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.
Kyrylo Reitor Chief Marketing Officer at International Fintech Business
15 November
Francesco Fulcoli Chief Compliance and Risk Officer at Flagstone
Nkahiseng Ralepeli VP of Product: Digital Assets at Absa Bank, CIB.
14 November
Jamel Derdour CMO at Transact365 / Nucleus365
13 November
Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.
Please read our Privacy Policy.