Skip to main content

Electronic locks in over 40,000 hotels worldwide compromised, says security firm

Security research firm F-Secure has discovered a critical vulnerability in electronic locks made by the world’s largest lock manufacturer, Assa Abloy. The vulnerability allowed F-Secure researchers to gain access to any locked room in hotels secured by one of Assa Abloy’s electronic lock systems — leaving roughly 40 thousand major hotels around the world potentially exposed.

“The researchers’ attack involves using any ordinary electronic key to the target facility – even one that’s long expired, discarded, or used to access spaces such as a garage or closet. Using information on the key, the researchers are able to create a master key with privileges to open any room in the building. The attack can be performed without being noticed,” F-Secure’s announcement reads.

Recommended Videos

With this exploit, F-Secure researchers were able to gain “master key” access to any hotel facility using Assa Abloy’s VingCard system — all they needed was a guest’s key card. Using off-the-shelf hardware, F-Secure’s researchers were able to read these key cards remotely — say, through your pocket — and using the same device, effectively circumvent the electronic key card system’s protections in just a matter of minutes, creating their own master keys out of thin air. To be clear though, this system is primarily used in the hospitality industry, and consumer Assa Abloy products are unaffected.

Image used with permission by copyright holder

“You can imagine what a malicious person could do with the power to enter any hotel room, with a master key created basically out of thin air,” said Tomi Tuominen, practice leader at F-Secure.

Tomi said F-Secure doesn’t believe anyone is currently using this exact exploit in the wild, which should help all you frequent travelers breathe a sigh of relief. Still, that doesn’t mean there aren’t similar vulnerabilities in electronic key card systems. After all, F-Secure’s odyssey to discover this vulnerability was kicked off after one of its researchers experienced a similar exploit firsthand.

“The researchers’ interest in hacking hotel locks was sparked a decade ago when a colleague’s laptop was stolen from a hotel room during a security conference. When the researchers reported the theft, hotel staff dismissed their complaint, given that there was not a single sign of forced entry, and no evidence of unauthorized access in the room entry logs,” the announcement continues.

F-Secure has been working hand in hand with Assa Abloy to mitigate this particular vulnerability and develop software patches for all affected hotel properties.

“I would like to personally thank the Assa Abloy R&D team for their excellent cooperation in rectifying these issues,” said Tuominen. “Because of their diligence and willingness to address the problems identified by our research, the hospitality world is now a safer place. We urge any establishment using this software to apply the update as soon as possible.”

Jaina Grey
Former Digital Trends Contributor
Jaina Grey is a Seattle-based journalist with over a decade of experience covering technology, coffee, gaming, and AI. Her…
No, a lifetime VPN subscription doesn’t mean ‘your’ lifetime
iPhone with VPN service enabled in hand over a blurred background

Folks who signed up for al lifetime subscription with VPN provider VPNSecure have been discovering the true definition of “lifetime” when it comes to such deals. And it’s not the one they'd hoped to hear.

After new owners took over the company, these particular customers recently had their lifetime subscriptions canceled. The new operator of VPNSecure told them that it didn’t know about the lifetime deals when they acquired the business, adding that it was unable to honor them.

Read more
SanDisk’s latest drive sets new benchmark for consumer NVMe SSDs
The SanDisk WD Black SN8100 PCIe Gen 5 SSD with and without heatsink variants

SanDisk has officially introduced the WD Black SN8100, its latest high-end PCIe Gen 5 NVMe SSD targeting PC enthusiasts, gamers, and professional users. With sequential read speeds of up to 14,900 MB/s and write speeds of 14,000 MB/s, the drive sets a new bar for consumer SSD performance, surpassing some of the best NVMe SSDs currently on the market, including the Crucial T705. 

The SN8100 uses a standard M.2 2280 form factor and is available in capacities of 1TB, 2TB, 4TB, and 8TB. It’s worth noting that the 1TB model offers lower write speeds, up to 11,000 MB/s, compared to the higher-capacity versions, which reach up to 14,000 MB/s. 

Read more
Pairing the RTX 5090 with a CPU from 2006? Nvidia said ‘hold my beer’
RTX 5090.

Nvidia's best graphics cards are often paired with expensive CPUs, but what if you want to try a completely mismatched, retro configuration? Well, that used to be impossible due to driver issues. But, for whatever reason, Nvidia has just removed the instruction that prevented you from doing so, opening the door to some fun, albeit nonsensical, CPU and GPU combinations.

The instruction in question is called POPCNT (Population Count), and this is a CPU instruction that also prevents Windows 11 from being installed on older hardware. Its job is counting how many bits are present in a binary number. However, as spotted by TheBobPony on X (Twitter), POPCNT will not be a problem for Nvidia's latest graphics cards anymore.

Read more