Skip to main content
  1. Home
  2. Computing
  3. News

Hilton latest high-end hotel group to be hit by hackers

Add as a preferred source on Google

Visited a Hilton hotel in the last 12 months? If so, you’d be wise to take a quick look through your payment card records to check everything’s in order.

The international hotel group confirmed on Tuesday that hackers targeted its point-of-sale systems in hotel restaurants, cafes, bars, and stores with malware designed to collect “cardholder names, payment card numbers, security codes, and expiration dates.” However, it added that no addresses or card personal identification numbers had been stolen.

Recommended Videos

The breach occurred at Hilton hotels, which include others in its group such as Embassy Suites, Doubletree, Hampton Inn and Suites, Homewood Suites, Conrad Hotels & Resorts, and Waldorf Astoria Hotels & Resorts, over a 17-week period from November 18 to December 5, 2014, and April 21 to July 27 this year, the company said in a release, adding, “You may want to review and monitor your payment card statements” if you used a card during any of the dates mentioned.

The incident first came to light in September this year when high-profile security expert Brian Krebs reported that “multiple sources” in the banking industry had uncovered evidence of credit card fraud that suggested hackers had “compromised point-of-sale registers in gift shops and restaurants at a large number of Hilton hotel” locations.

We’ve asked the company why it took so long to confirm to its customers a security breach that others appeared to be aware of several months ago and will update if we hear back.

Hilton on Tuesday advised its customers to contact their financial institution directly should they detect any irregular activity on their card statements.

In a bid to reassure visitors to its hotels, the company said it’d “further strengthened” its systems and was currently working with law enforcement to try to identify the hackers.

The point-of-sale systems of high-end hotel groups are clearly a popular target for hackers. Just last month the Trump hotel chain confirmed a year-long data hack while back in March Mandarin Oriental reported a malware attack at a number of its hotels around the world.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Comu’s tiny AI recorder can turn your meetings into slides, emails, and action plans
Comu Action Pro records for up to 70 hours and supports more than 113 languages
Comu Action Pro AI voice recorder in hand

AI voice recorders that can capture meetings, transcribe conversations, and generate summaries are becoming increasingly common. Flowtica's Scribe, for example, puts those capabilities inside a pen that can also be used for handwritten notes.

Comu, formerly known as Comulytic, is taking the concept a step further with the Action Pro, which is a pocket-sized AI recorder capable of turning recorded conversations into editable presentations, follow-up emails, meeting briefs, documents, and action plans. The device has a dedicated AI button that lets users request these materials using voice commands.

Read more
Microsoft threatened legal action, and this researcher just dropped a new Windows bug anyway
Windows Defender was supposed to protect you. Right now, it's the problem.
Microsoft account

Microsoft's legal threats clearly didn't scare off security researcher Nightmare Eclipse. Just weeks after the company warned it might pursue researchers who release undisclosed bugs outside its official channels, Nightmare Eclipse published a fresh Windows vulnerability, and it's a nasty one.

What exactly does ShieldBreak do?

Read more
Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop
AI made phishing too easy, so Microsoft is closing the door on SMS logins.
Computer, Electronics, Laptop

Microsoft just sent a warning to IT admins, and it's a big one. The company wants everyone to stop using SMS and voice-based authentication, and it's citing AI-powered phishing as the main reason.

Why is Microsoft killing SMS authentication?

Read more