Security & Fraud

Hyatt Hotels’ Payment Data Breached

Shutterstock

Hyatt Hotels’ customers received a not-so-happy holiday gift last week when the hotel group announced its payment system was recently impacted by malware activity.

“We recently identified malware on computers that operate the payment processing systems for Hyatt-managed locations,” a statement from Hyatt Hotels Global President of Operations Chuck Floyd explained.

“As soon as we discovered the activity, we launched an investigation and engaged leading third-party cybersecurity experts,” Floyd continued.

According to a press release from the company containing a similar message, an investigation into the payment system breach is ongoing, and customers should continue to keep a close watch on their payment card account statements for any unauthorized charges.

Stephanie Sheppard, a spokeswoman for Hyatt Hotels, told Reuters the credit card-stealing malware attack was discovered on Nov. 30 but was unable to confirm how many of the hotel chain’s locations were impacted, how long its network was left vulnerable and if any payment card data was actually stolen.

The data breach at Hyatt Hotels is just the latest in a string of recent cyberattacks on businesses within the hospitality industry.

Just last month, the world’s largest hotel company, Starwood Hotels & Resorts, announced some of its hotel locations were hit by a malware attack. The payment systems of 54 Starwood hotels in North America were infected with a malware designed to compromise payment card data, Reuters reported at the time. The breach enabled unauthorized parties to gain access to sensitive information, such as payment card number, cardholder name, security code and expiration date.

Trump Hotels, Hilton Hotels, Mandarin Oriental Hotel Group and hotel management group White Lodging Services have all reported and investigated breaches to their payment and/or point-of-sale systems this year.

——————————

PYMNTS LIVE ROUNDTABLE: TUESDAY, JULY 14, 2020 AT 12:00 PM (ET)

Digital transformation has been forcefully accelerated, but how does that agility translate into the fight against COVID-era attacks and sophisticated identity threats? As millions embrace online everything, preserving digital trust now falls mostly on banks and FIs. Now, advances in identity data and using different weights on the payment mix afford new opportunities to arm organizations and their customers against cyberthreats. From the latest in machine learning for fraud and risk, to corporate treasury teams working in new ways with new datasets, learn from experts how digital identity, together with advances like real-time payments, combine to engender trust and enrich relationships.

TRENDING RIGHT NOW