Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Network Security Viruses & Malware Cybercrime Security Solutions More Topics...
Data Security
24/7/365 Network Uptime!
Average Rating:
Rate this article:  
Major Hotel Customers Hit by Data Breach
Major Hotel Customers Hit by Data Breach

By Jennifer LeClaire
February 3, 2014 2:25PM

Bookmark and Share
The breach appears to have affected mainly restaurants, gift shops and other concerns within hotels like Marriott managed by White Lodging -- not the property management systems that run the hotel front desk computers. For example, the breach impacted only Marriott guests who used their cards at White Lodging-managed gift shops and restaurants.
 


After the Target and Niemen Marcus network breaches, retailers are now hyper-vigilant about security. But the hotel industry may need to open its eyes a little wider.

White Lodging, a company that maintains hotel franchises under nationwide brands including Hilton, Marriott, Sheraton and Westin, appears to have suffered a data breach that exposed credit and debit card information on thousands of guests throughout much of 2013, according to KrebsOnSecurity.

“Earlier this month, multiple sources in the banking industry began sharing data indicating that they were seeing a pattern of fraud on hundreds of cards that were all previously used at Marriott hotels from roughly March 23, 2013 on through the end of last year,” said Brian Krebs, a security expert who runs the blog. “But those same sources said they were puzzled by the pattern of fraud, because it was seen only at specific Marriott hotels, including locations in Austin, Chicago Denver, Los Angeles, Louisville and Tampa.”

Marriott Speaks Out

As it turns out, Krebs said, the common thread among all those Marriott locations is the management company: Merrillville, Ind.-based White Lodging Services Corp. White Lodging bills itself as “a fully-integrated owner, developer and manager of premium brand hotels.” The Web site suggests its portfolio includes 168 full-service hotels in 21 states. That includes more than 30 restaurants.

“White Lodging declined to offer many details, saying in an emailed statement that “an investigation is in progress, and we will provide meaningful information as soon as it becomes available,” Krebbs said. He noted that Marriott also issued a statement explaining that one of its franchisees has experienced unusual fraud patterns in connection with its systems that process credit card transactions at a number of hotels across a range of brands, including some Marriott-branded hotels.

“They are in the midst of the investigation and are in close contact with the banks and credit cards companies. We are working closely with the franchisee as they investigate the matter,” Marriott said. “Because the suspected breach did not impact any systems that Marriott owns or controls, we do not have additional information to provide. As this impacts customers of Marriott hotels we want to provide assurance that Marriott has a long-standing commitment to protect the privacy of the personal information that our guests entrust to us, and we will continue to monitor the situation closely.”

More Breaches to Come

Krebs notes that sources say the breach appears to have affected mainly restaurants, gift shops and other establishments within hotels managed by White Lodging -- not the property management systems that run the hotel front desk computers, which handle the checking in and out of guests.

“In the case of Marriott, for example, all Marriott establishments operated as franchises must use Marriott’s property management system,” he said. “As a result, the breach impacted only those Marriott guests who used their cards at White Lodging-managed gift shops and restaurants.”

We caught up with Tommy Chin, a technical support engineer at CORE Security, to get his take on the breach. He told us Kaptoxa, a new piece of malware, has infected a large number of retail information systems, according to a report from iSightPartners.

“Their report states you may be at risk if you have a POS system in operation. I believe there will be a good number of disclosed breached coming in the near future -- not just from retailers,” Chin said. “I’m sure that all the breaches to date have not yet been discovered.”
 

Tell Us What You Think
Comment:

Name:



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Data Security
1.   Juniper DDoS for High-IQ Networks
2.   Google Hacker Team to Hunt Bugs
3.   Cloud Firms Offer Azure Starter Kit
4.   FBI Cyber-Expert's Humble Start
5.   Chinese Hackers Hit U.S. Officials


advertisement
Gartner Rates IT Security Companies
IBM, HP, McAfee, Splunk ranked well.
Average Rating:
Hackers Target Western Energy Firms
Appears to be state-sponsored group.
Average Rating:
IBM Uncovers Android Security Flaw
Ten percent of devices at risk.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
34 European Banks Hit by Android-Skirting Malware
Criminals have been finding gaping holes in Android-based two-factor authentication systems that banks around the world are using. The result: 34 banks in four European countries have been hit.
 
New Web Tracking Technologies Defeat Privacy Protections
Recently developed Web tracking tools are able to circumvent even the best privacy defenses, according to a new study by researchers at Princeton and the University of Leuven in Belgium.
 
Juniper DDoS Solution Aims at High-IQ Networks
In the face of more complex attacks, Juniper Networks is boosting its DDoS Secure solution to help companies mitigate the threats with more effective security intelligence throughout the network fabric.
 

Mobile Technology Spotlight
Nvidia Revamps Shield as an Android Game Tablet
Going after hardcore PC gamers, Nvidia is releasing a gaming-focused tablet that works with a controller. The Shield Tablet follows the Shield Portable gaming handheld Nvidia released last year.
 
Apple Patent for Smart Watch Comes to Light
Does a new smart watch patent issued to Apple provide a preview of the expected wearable from the tech giant? Some Apple-watchers are parsing the patent for signs of the coming product.
 
Will iPhone 6 Cannibalize Apple's Tablet Sales?
Could Apple’s iPhone 6 -- it’s so-called super-size phone due to hit store shelves this fall -- come back to haunt the smartphone maker? Some observers say yes; others say preposterous.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Cybercrime | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.