Holiday bookings in Poland under the microscope. The data of hundreds of tourists was leaked
The data of hundreds of tourists who planned to stay in Polish hotels was leaked. “We managed to read the data of approximately 2,000 reservations,” said Hotres.
Niebezpiecznik.pl was the first to report the situation on July 3. As reported, the incident was reported to the website by a reader who serves the IT side of one of the Polish hotels that uses the Hotres system to manage reservations in the facility.
Hotel guest data leak. How did this happen?
According to information provided to TVN 24 by Hotres, a security breach was actually recorded on June 29. At night, there was a massive attack from many IP addresses, as a result of which an unauthorized person gained access to reservation data.
“The hacker managed to read the data of approximately 2,000 reservations. These were mainly holiday reservations – the hacker was looking for stays in July and August. Unfortunately, we do not have data on which reservations were obtained” – the company said in information sent to TVN 24.
A reader of niebezpiecznik.pl informed that from July 2 “customers who have a reservation (in the hotel – ed.) receive messages on Whatsapp about the reservation with detailed data and a payment link, which is an attempt to extort payment. The situation is not a single case and customers of other hotels also receive them”.
Therefore, you should pay special attention to the messages you receive regarding leisure. Before taking any steps, it is worth contacting the facility itself and making sure that the messages come from the hotel.
Data leak regarding hotel guests. What information was captured?
According to information provided by niebezpiecznik.pl, cybercriminals allegedly obtained the following data from tourists: name and surname, e-mail address, telephone numbers, dates of stay, as well as information about the amount of accommodation.
To check whether a given hotel uses the Hotres system, you can only: “search your mailbox for the word ‘hotres’ – some of the e-mails from the facility may (but do not have to!) contain the name of the system” – reported niebezpiecznik.pl. Persons whose data may be at risk should also be informed of this possibility by the hotel itself.
