Best Western downplays hack attack
August 28, 2008 |
Hotel chain Best Western issued a statement downplaying concerns over a recent hack attack that was reported to have put at risk the personal details of all its customers since 2007.
This statement is intended to provide further detail on the largely erroneous story originated by The Sunday Herald newspaper in Scotland, concerning the breach of Best Western?s Central Reservations System.
We can confirm that on August 21, 2008, three separate attempts were made via a single log-on ID to access the same data from a single hotel. The hotel in question is the 107-room Best Western Hotel am Schloss Kopenick in Berlin, Germany, where a Trojan horse virus was detected by the hotel?s anti-virus software. The compromised log-in ID permitted access to reservations data for that property only. The log-in ID was immediately terminated, and the computer in question has been removed from use.
We can also confirm that we have been able to narrow down the number of customers affected by this breach to ten. We are currently contacting those customers and offering assistance as needed.
We are working with the FBI and international authorities to investigate further.
Points of note:
- The compromised user ID permitted access only to the reservations at a single hotel, and there is no evidence of unauthorized access to data for any other Best Western hotel.
- Best Western purges reservations data within seven days of guest departure, thereby limiting potential data exposure to (1) guests who departed up to one week prior to the exposure; (2) current guests; and (3) future guests of that particular hotel.
- There is no evidence of any unauthorized access to any other customer data.
In the day-to-day conduct of our business, we comply with the Payment Card Industry (PCI) Data Security Standards (DSS). To maintain that compliance, Best Western maintains a secure network protected by firewalls and governed by a strong information security policy. We regularly test our systems and processes in an effort to protect customer information, and employ the services of industry-leading third-party firms to evaluate our safeguards. We also delete credit card information and all other personal information upon guest departure.
Given the nature of IT security, absent evidence of actual attempts to enter our system without authorization, Best Western?s highest level of response must consist of the following: (1) to continue to monitor for such activity; (2) to assist law enforcement authorities and our credit card partners with their investigation; (3) to amplify our already stringent data security regime, which is of course compliant with PCI standards; (4) to reinforce best data protection practices at our 4000 worldwide hotels. We are actively engaged in all four of these areas, on behalf of our valued customers and member hotels.
Related: "Revealed: 8 million victims in the world's biggest cyber heist" by The Sunday Herald
Latest Industry News
Mobile and its impact on hotel revenue management
16 May, 2012 | Hotel Marketing
Top luxury travel trends in China
16 May, 2012 | Online Travel
Americans warming up to summer travel in 2012
16 May, 2012 | Hotel Marketing
How to capture early bird summer travel bookers
16 May, 2012 |
New Facebook study shows brands how to build engagement
16 May, 2012 | Online Marketing
How Amazon killed book critics
16 May, 2012 | Online Marketing
The problem with hotel compliance
15 May, 2012 | Hotel Marketing
Travelocity launches hotel connectivity platform
15 May, 2012 |
Room Key adds Travelocity hotel content to “satisfy needs of consumers”
15 May, 2012 | Hotel Marketing
Many would-be travelers still not spending
15 May, 2012 | Online Travel
More on the dramatic impact digital has made on travel purchases
15 May, 2012 | Online Travel
HRS mobile hotel bookings on the rise
15 May, 2012 | Online Travel
Expedia betting the bank on social and mobile
14 May, 2012 | Online Travel
Room Key exits beta, launches new tools
14 May, 2012 | Online Travel
Google urged to up its game on travel reviews
14 May, 2012 | Online Travel
Most Popular Articles
The European hospitality industry is calling for fairer practices in Online-Distribution
11 May, 2012 | Hotel Marketing
Mobile searches may yield better hotel deals
11 May, 2012 | Hotel Marketing
New Shangri-La Hotels website gets more social, faster booking
11 May, 2012 | Hotel Marketing
Expedia betting the bank on social and mobile
14 May, 2012 | Online Travel
Room Key exits beta, launches new tools
14 May, 2012 | Online Travel
Mac users book fancier hotels than PC users
11 May, 2012 | Hotel Marketing
At long last, U.S. launches national tourism strategy
11 May, 2012 | Online Travel
Americans now spend more time on Facebook mobile than its website
14 May, 2012 | Online Marketing
Google urged to up its game on travel reviews
14 May, 2012 | Online Travel
Hilton: Technology drives new design innovations
11 May, 2012 | Hotel Marketing
Latest Company News
Availpro launches its new Direct Click Manager service
11 May, 2012 | Hotel Marketing
SiteMinder receives $5 Million investment to fund global expansion
10 May, 2012 | Hotel Marketing
RateGain awarded qualified vendor status with Choice Hotels International
10 May, 2012 | Hotel Marketing
eRevMax expands its India presence with new office in Bengaluru
10 May, 2012 | Hotel Marketing
Lodging Interactive launches website analytics & social tool
10 May, 2012 | Hotel Marketing
Pegasus launches RezView Intelligence
26 Apr, 2012 | Hotel Marketing
HSMAI Revenue optimization conference to focus on RM evolution
27 Mar, 2012 | Hotel Marketing
De Vere partners with SiteMinder
27 Mar, 2012 | Hotel Marketing
Lodging Interactive launches website analytics & social tool
27 Mar, 2012 | Hotel Marketing
How good is your hotel’s social media?
21 Mar, 2012 | Hotel Marketing
TravelClick launches Rate360
29 Feb, 2012 | Hotel Marketing
Appnostic partners with GoMio
29 Feb, 2012 | Hotel Marketing
SiteMinder predicts trends for online hotel distribution for 2012
29 Feb, 2012 | Hotel Marketing
Hotels4u.com added to RateGain’s channel management solution
29 Feb, 2012 | Hotel Marketing
Availpro and EasyRMS come together to boost hotel revenue
08 Feb, 2012 | Hotel Marketing























