Dear Padgett-Beale guests,
Some of you may or may not already be aware that cyberattacks
are being focused towards hotels. Here at Padgett-Beale, our goal
is always to ensure our guests safety, privacy, and comfort is of
highest priority. Please be aware that our cybersecurity staff are
taking every measure to eliminate any attacks as well as solve
any issues that may arise. Due to past and current reports we
have policies and protocols to help secure as well as monitor any
behavior that might be a cyberattack. I assure you we have the
top of the line cybersecurity professionals and software to
protect you, our guests.
The following information is to inform you of what’s
happening with hotels and their cybersecurity programs. Our
intention is not to frighten you, but to help make you feel
comfortable knowing we are doing everything possible to prevent
any of the following below. The information from here on in are
reports from past attacks and reports concerning breaches within
the hotel networks. The culprits were hackers who used
ransomware as well as hotel Wi-Fi to spy and steal guest’s data. I
can’t say this enough, but we are prepared to recover from and
counter attempts from hackers.
Malware is short for malicious software. It is a general term used
to refer to a variety of hostile or intrusive softwares. Malware
attaches itself to the components of a web page, pop-up
advertisements, toolbars, or free applications that users download.
Once inside a system, it steals information stored on that
computer such as social security numbers, passwords, and bank
account details. The following are the type of malware mentioned
above.
• Ransomware: Ransomware is a malware which prevents
users from accessing their computer systems. After finding
its way into a system, it encrypts all the files on it and holds
the password which can decrypt it, ransom. Ransomware is
similar to kidnapping a person—the person would only be
released when ransom has been paid, and here the data is
only retrieved when the ransom was paid. Just like in
kidnapping, paying the ransom doesn’t guarantee the safety
of the data. Ransomware may be downloaded by users by
logging on to compromised or malicious websites. It also is
delivered in the form of an attachment in emails. Crowti is
one of the prime examples of ransomware. (EC-Council,
2016)
• Spyware: This malware spies on user activity without their
knowledge. Users enter their personal information on retail
websites in the form of shipping address and credit card
details. Using spyware these details are extracted and
exploited. Additionally, spyware also modifies browser
security settings to make it more vulnerable. Spyware is
usually bundled along with the free applications which are
downloaded from the internet. It spreads by exploiting
software vulnerabilities. (EC-Council, 2016)
• Rootkit - Rootkit is malicious software designed to remotely
access or control a computer without alerting the users or
the security programs. Once the rootkit is installed,
malicious parties remotely access the files, modify security
settings, steal crucial information, or control the computer
and use it to attack other computers. Rootkit prevention,
detection, and removal is difficult due to its stealthy
operation. Hence rootkit detection is only done manually
through regular scans and monitoring. Users can protect
their computers from rootkit by frequently updating
software, applications, operating systems, and virus
definitions (used to update the antivirus software on a
system), avoiding suspicious downloads, and carrying out
scans to check for malware. (EC-Council, 2016)
“According to English-language European news
outlet The Local, people staying at the Austrian hotel couldn’t use
their key cards to enter their rooms; it was also not possible to
program new key cards. The establishment’s reservation system
and the cash desk system were also taken down by the hackers”,
(Ghoshal, 2017). This was a ransomware attack which ended up
being resolved by paying a ransom and replacing their system.
The other attack was spyware. “Hotel Wi-Fi hotspots are
compromised in order to help deliver the payload to the selected
pool of victims. The exact methods of compromise remain
uncertain, but cybersecurity experts believe it involves attackers
remotely exploiting vulnerabilities in server software or infiltrating
the hotel and gaining physical access to the machines”, (Palmer,
2017). The last attack mentioned is rootkit. Geuss (2016) stated
that HEI Hotels & Resorts payment systems for 20 of its
locations had been infected with malware that may have been
able to steal tens of thousands of credit card numbers and
corresponding customer names, expiration dates, and verification
codes. He also stated HEI claims that it did not lose control of
any customer PINs, as they are not collected by the company’s
systems.
You probably asking the following question. How are we going to
prevent hackers from doing what they have done to others? The
following is a few items we have implemented into one of our
policies.
• Regularly backup of our data
• Protect against malware and viruses
• Prioritize password security
• Check and update anti-virus software
• Know when to trust your software provider
(SiteMinder, 2019)
Please keep in mind that your trust and comfort is the most
important factor for us in regards to our guest. Have trust and
comfort in us as we protect you against cyberattacks as you
enjoy yourself.
Very respectfully,
EC-Council (2016). Certified Secure Computer User (CSCU)
Version 2 eBook (2nd Edition). International Council of E-
Commerce Consultants (EC Council Retrieved March 27, 2022,
from https://evantage.gilmoreglobal.com/books/9781635671810.
Geuss, M. (2016, August 15). 20 hotels suffer hack costing tens
of thousands their credit card information. Ars Technica.
Retrieved March 27, 2022, from
https://arstechnica.com/information-technology/2016/08/20-
hotels-suffer-hack-costing-tens-of-thousands-their-credit-card-
information/.
Ghoshal, A. (2017, January 30). Hackers use ransomware to target
hotel guests’ door locks. TNW | Security. Retrieved March 27,
2022, from https://thenextweb.com/news/hackers-use-
ransomware-to-lock-hotel-guests-in-their-rooms.
Palmer, D. (2017, July 20). Hackers are using hotel Wi-Fi to spy
on guests, steal data. ZDNet. Retrieved March 27, 2022, from
https://www.zdnet.com/article/hackers-are-using-hotel-wi-fi-to-
spy-on-guests-steal-data/.
SiteMinder. (2019, December 18). Hotel data breaches: What
independent hoteliers need to know about data security.
Retrieved March 27, 2022, from
https://www.siteminder.com/r/hotel-data-breaches/#-hotel-data-
security-tips-to-action-now.