Skip to main content

Hilton latest high-end hotel group to be hit by hackers

hilton hotels
Visited a Hilton hotel in the last 12 months? If so, you’d be wise to take a quick look through your payment card records to check everything’s in order.

The international hotel group confirmed on Tuesday that hackers targeted its point-of-sale systems in hotel restaurants, cafes, bars, and stores with malware designed to collect “cardholder names, payment card numbers, security codes, and expiration dates.” However, it added that no addresses or card personal identification numbers had been stolen.

The breach occurred at Hilton hotels, which include others in its group such as Embassy Suites, Doubletree, Hampton Inn and Suites, Homewood Suites, Conrad Hotels & Resorts, and Waldorf Astoria Hotels & Resorts, over a 17-week period from November 18 to December 5, 2014, and April 21 to July 27 this year, the company said in a release, adding, “You may want to review and monitor your payment card statements” if you used a card during any of the dates mentioned.

The incident first came to light in September this year when high-profile security expert Brian Krebs reported that “multiple sources” in the banking industry had uncovered evidence of credit card fraud that suggested hackers had “compromised point-of-sale registers in gift shops and restaurants at a large number of Hilton hotel” locations.

We’ve asked the company why it took so long to confirm to its customers a security breach that others appeared to be aware of several months ago and will update if we hear back.

Hilton on Tuesday advised its customers to contact their financial institution directly should they detect any irregular activity on their card statements.

In a bid to reassure visitors to its hotels, the company said it’d “further strengthened” its systems and was currently working with law enforcement to try to identify the hackers.

The point-of-sale systems of high-end hotel groups are clearly a popular target for hackers. Just last month the Trump hotel chain confirmed a year-long data hack while back in March Mandarin Oriental reported a malware attack at a number of its hotels around the world.

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Hacking-as-a-service lets hackers steal your data for just $10
A depiction of a hacker breaking into a system via the use of code.

A new (and cheap) service that offers hackers a straightforward method to set up a base where they manage and perform their cyber crimes has been discovered -- and it’s gaining traction.

As reported by Bleeping Computer, security researchers unearthed a program called Dark Utilities, effectively providing a command and control (C2) center.

Read more
This anti-hacker group helps you escape ransomware for free
A depiction of a hacked computer sitting in an office full of PCs.

This week marks the sixth anniversary of the No More Ransom project, an initiative aimed at helping ransomware victims.

Operating as an online platform to help anyone who’s experiencing trouble after their system has been infected by some form of ransomware, No More Ransom was formed as a joint venture between law enforcement (Europol and the Dutch National Police) alongside IT security firms (Kaspersky and McAfee).

Read more
Hackers now exploit new vulnerabilities in just 15 minutes
A depiction of a hacker breaking into a system via the use of code.

Hackers are now ​​moving faster than ever when it comes to scanning vulnerability announcements from software vendors.

Threat actors are actively scanning for vulnerable endpoints within a period of just 15 minutes once a new Common Vulnerabilities and Exposures (CVE) document is published, according to Palo Alto's 2022 Unit 42 Incident Response Report.

Read more