{"id":6515,"date":"2017-02-06T10:17:43","date_gmt":"2017-02-06T18:17:43","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/02\/06\/news-343\/"},"modified":"2017-02-06T10:17:43","modified_gmt":"2017-02-06T18:17:43","slug":"news-343","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/02\/06\/news-343\/","title":{"rendered":"InterContinental Confirms Breach at 12 Hotels"},"content":{"rendered":"<p><strong>InterContinental Hotels Group (IHG)<\/strong>, the parent company for thousands of\u00a0hotels worldwide including <strong>Holiday Inn<\/strong>, acknowledged Friday that a credit card breach impacted at least a dozen properties nationwide. News of the breach was <a href=\"https:\/\/krebsonsecurity.com\/2016\/12\/holiday-inn-parent-ihg-probes-breach-claims\/\" target=\"_blank\">first reported<\/a> by KrebsOnSecurity\u00a0more than a month ago.<\/p>\n<div id=\"attachment_37957\" style=\"width: 300px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-37957\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/02\/topofmark.png\" alt=\"Top of the Mark, San Francisco, one of the bars impacted by the IHG card breach.\" width=\"290\" height=\"292\" \/><\/p>\n<p class=\"wp-caption-text\">Top of the Mark, San Francisco, one of the bars impacted by the IHG card breach.<\/p>\n<\/div>\n<p>In <a href=\"http:\/\/www.prnewswire.com\/news-releases\/ihg-notifies-guests-of-payment-card-incident-at-12-properties-in-the-americas-300401996.html\" target=\"_blank\">a statement<\/a> issued late Friday, IHG said it found malicious software installed on point of sale servers at restaurants and bars of 12 IHG-managed properties between August and December 2016. The stolen data included information stored on the magnetic stripe on the backs of customer credit and debit cards &#8212; the cardholder name, card number, expiration date, and internal verification code.<\/p>\n<p>A list of the known breached locations is <a href=\"https:\/\/www.ihg.com\/content\/us\/en\/customer-care\/protecting-our-guests\" target=\"_blank\">here<\/a>.\u00a0IHG said cards used at the front desk of these properties were not affected.<\/p>\n<p>According to IHG, we may not yet know the full scope of this breach: The company advised that its investigation into other properties in the Americas region is ongoing.<\/p>\n<p>Card-stealing cyber thieves have broken into some of the largest hotel chains over the past few years. Hotel brands that have acknowledged card breaches over the last year after prompting by KrebsOnSecurity include <a href=\"https:\/\/krebsonsecurity.com\/2016\/09\/kimpton-hotels-acknowledges-data-breach\/\" target=\"_blank\">Kimpton Hotels<\/a>,\u00a0<a href=\"http:\/\/krebsonsecurity.com\/2015\/07\/banks-card-breach-at-trump-hotel-properties\/\" target=\"_blank\">Trump Hotels<\/a> (<a href=\"http:\/\/krebsonsecurity.com\/2016\/04\/sources-trump-hotels-breached-again\/\" target=\"_blank\">twice<\/a>), <a href=\"http:\/\/krebsonsecurity.com\/2015\/09\/banks-card-breach-at-hilton-hotel-properties\/\" target=\"_blank\">Hilton<\/a>, <a href=\"http:\/\/krebsonsecurity.com\/2015\/03\/credit-card-breach-at-mandarian-oriental\/\" target=\"_blank\">Mandarin Oriental<\/a>, and <a href=\"http:\/\/krebsonsecurity.com\/2014\/01\/hotel-franchise-firm-white-lodging-investigates-breach\/\" target=\"_blank\">White Lodging<\/a> (<a href=\"http:\/\/krebsonsecurity.com\/2015\/04\/white-lodging-confirms-second-breach\/\" target=\"_blank\">twice<\/a>). Card breaches also have hit hospitality\u00a0chains <a href=\"http:\/\/krebsonsecurity.com\/2015\/11\/starwood-hotels-warns-of-credit-card-breach\/\" target=\"_blank\">Starwood Hotels<\/a>\u00a0and <a href=\"http:\/\/krebsonsecurity.com\/2016\/01\/hyatt-card-breach-hit-250-hotels-in-50-nations\/\" target=\"_blank\">Hyatt<\/a>.<span id=\"more-37956\"><\/span><span id=\"more-36174\"><\/span><\/p>\n<p>In many of those incidents, thieves planted malicious software on the point-of-sale devices at restaurants and bars inside of the hotel chains.\u00a0Point-of-sale based malware has driven most of the credit card breaches over the past two years, including intrusions at <a href=\"https:\/\/krebsonsecurity.com\/?s=target+breach&amp;x=0&amp;y=0\" target=\"_blank\">Target<\/a> and <a href=\"https:\/\/krebsonsecurity.com\/?s=home+depot+breach&amp;x=0&amp;y=0\" target=\"_blank\">Home Depot<\/a>, as well as breaches at <a href=\"https:\/\/krebsonsecurity.com\/?s=point-of-sale+vendor&amp;x=0&amp;y=0\" target=\"_blank\">a slew of point-of-sale vendors<\/a>. The malware usually is installed via hacked remote administration tools. Once the attackers have their malware loaded onto the point-of-sale devices, they can remotely capture data from each card swiped at that cash register.<\/p>\n<p>Thieves can then <a href=\"https:\/\/krebsonsecurity.com\/2014\/06\/peek-inside-a-professional-carding-shop\/\" target=\"_blank\">sell that data to crooks<\/a> who specialize in encoding the stolen data onto any card with a magnetic stripe, and using the cards to purchase high-priced electronics and gift cards from big-box stores like Target and Best Buy.<\/p>\n<p>Readers\u00a0should remember that they\u2019re not\u00a0liable for fraudulent charges on their credit or debit cards, but they still have to report the unauthorized transactions. There is no substitute for keeping a close eye on your card statements. Also, consider using credit cards instead of debit cards; having your checking account emptied of cash while your bank sorts out the situation can be a hassle and lead to secondary problems (bounced checks, for instance).<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2017\/02\/intercontinental-confirms-breach-at-12-hotels\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/02\/topofmark.png\"\/><br \/>InterContinental Hotels Group (IHG), the parent company for thousands of hotels worldwide including Holiday Inn, acknowledged Friday that a credit card breach impacted at least a dozen properties nationwide. News of the breach was first reported by KrebsOnSecurity more than a month ago.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[11217,11218,10646,10647,11219,10644],"class_list":["post-6515","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-holiday-inn","tag-ihg","tag-ihg-breach","tag-intercontinental-hotels-group","tag-intercontinental-hotels-group-breach","tag-other"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6515","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6515"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6515\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6515"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6515"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6515"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}