City
Epaper

Hackers stealing guests' credit card data from hotels worldwide

By IANS | Updated: December 3, 2019 17:00 IST

Over 20 hotels in Asia, Latin America and Europe have fallen victim to targeted malware attacks, putting travellers' credit card data which is stored in a hotel administration system, including those received from online travel agencies (OTAs), at risk of being stolen and sold to criminals worldwide, warns a report from cybersecurity firm Kaspersky.

Open in App

Even more hotels are potentially affected across the globe, said the study.

The research studied the RevengeHotels campaign that includes different groups using traditional Remote Access Trojans (RATs) to infect businesses in the hospitality sector.

The campaign has been active since 2015 but has gone on to increase its presence in 2019.

At least two groups, RevengeHotels and ProCC, were identified to be part of the campaign, however more cybercriminal groups are potentially involved, said the study.

The main attack vector in this campaign was found to be emails with crafted malicious Word, Excel or PDF documents attached.

Each spear-phishing email was crafted with special attention to detail and usually impersonating real people from legitimate organizations making a fake booking request for a large group of people.

Even careful users could be tricked to open and download attachments from such emails as they include an abundance of details (for instance, copies of legal documents and reasons for booking at the hotel) and looked convincing, the research said.

"As users grow wary of how protected their data truly is, cybercriminals turn to small businesses, which are often not very well protected from cyberattacks and possess a concentration of personal data," said Dmitry Bestuzhev, Kaspersky's Head of Global Research and Analysis Team for Latin America.

"Hoteliers and other small businesses dealing with customer data need to be more cautious and apply professional security solutions to avoid data leaks that could potentially not only affect customers, but also damage hotel reputations as well," Bestuzhev added.

Once infected, the computer could be accessed remotely by the cybercriminal group. Evidence collected by Kaspersky researchers showed that remote access to hospitality desks and the data they contain is sold on criminal forums on a subscription basis.

Kaspersky telemetry confirmed targets in Argentina, Bolivia, Brazil, Chile, Costa Rica, France, Italy, Mexico, Portugal, Spain, Thailand and Turkey.

However, based on data extracted from Bit.ly, a popular link shortening service used by the attackers to spread malicious links, Kaspersky researchers assume that users from many other countries have at least accessed the malicious link - suggesting that the number of countries with potential victims could be higher.

( With inputs from IANS )

Tags: KasperskyCosta RicaThailandSpain
Open in App

Related Stories

MumbaiMaharashtra: Cyber Cell Rescues 60 Indians Trapped in Cyber Slavery in Myanmar, Thailand

InternationalEarthquake of Magnitude 4.7 on Richter Scale Hits Afghanistan

InternationalMyanmar Earthquake: 15 Killed, Several Injured as Mosque and Wailuwun Monastery Collapse Due to Strong Tremors (Watch Videos and Photos)

NationalEarthquake in Myanmar and Thailand: Authorities To Be on Standby, Says PM Narendra Modi

InternationalEarthquake in Thailand: Under-Construction Skyscraper Collapses in Bangkok Amid 7.7-Magnitude Tremors; Dramatic Video Goes Viral

International Realted Stories

International"Shock for the world": Russian MLA Abhay Kumar Singh on Pahalgam terror attack

InternationalPresident Droupadi Murmu departs for Vatican City to attend Pope Francis' State Funeral

InternationalJoe Kasper steps down as Chief of Staff to Defence Secretary Hegseth, moves to advisory role

International'France stands firmly with India and continue fight against terrorism', says President Macron; dials PM Modi on Pahalgam terror attack

InternationalPresident Droupadi Murmu departs for Vatican City to attend state funeral of Pope Francis