Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Stayed at a Best Western since 2007?  (Read 3936 times)

guest

  • Guest
Stayed at a Best Western since 2007?
« on: August 24, 2008, 12:44:03 AM »

If you have and if you reserved the room via the online reservation system then be prepared for possible credit card fraud :

http://www.sundayherald.com/news/heraldnews/display.var.2432225.0.0.php

Ignoring the inflated figures, this is bad. Really bad. I've seen what's on MemberWeb (that's what hotels call it) and it would indeed be possible to put together "burglary packs" as The Herald calls them. ID theft? In some instances yes, no problem as there will be passport/visa numbers, DoB, bank account numbers, addresses, flights etc etc. CC fraud? Trivial and everything is there to do cardholder not present transactions.

It shouldn't be possible for staff from one hotel to modify another hotels booking (BW hotels are independently owned, not a chain) but it is so there's no real separation, which is how I assume one login harvested that many records.

The only surprise is that it needed a trojan to steal the password. The staff usually can't remember the alphanumeric case-sensitive passwords so they have it written down somewhere - on the wall, in plain view in one hotel I was in  :-X

I do hope that this is just the European database rather than the UK database which has been compromised. Now perhaps the wisdom of SecurID keyfobs or similar might become clear. Then again who's going to pay for that?

Edit - I've recommended to people for some time now that you have a throwaway card for hotels. There are prepay ones now which are ideal for this.
« Last Edit: August 24, 2008, 12:53:06 AM by rizla »
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33930
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Stayed at a Best Western since 2007?
« Reply #1 on: August 24, 2008, 09:21:05 AM »

Quote
every single customer that has booked into one of Best Western's 1312 continental hotels since 2007
the stolen data includes a range of private information including home addresses, telephone numbers, credit card details and place of employment.

:(

Quote
succeeded in bypassing the system's security software and placing a Trojan virus on one of the Best Western Hotel machines used for reservations. The next time a member of staff logged in, her username and password were collected and stored.

I cant believe it was that easy,  :o so by going access to just one hotel PC, theyve been able to access the whole database?
Like you say rizla Im amazed that theres no hotel separation...  and if this is the case then its surprising that the system hasnt been compromised way before now. 
Staff in one hotel shouldnt be able to access private information about anyone whose stayed anywhere in any one of the other of the group hotels unless theyve also stayed in that particular hotel.

Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

guest

  • Guest
Re: Stayed at a Best Western since 2007?
« Reply #2 on: August 24, 2008, 12:48:04 PM »

The rest of the media are beginning to pick up on the story :

http://www.telegraph.co.uk/news/uknews/2613095/Hackers-steal-details-of-millions-of-Best-Western-hotel-guests.html

Edit - PA has it @ 14:30 so I'd guess the BBC will notice tonight. Or maybe not as most of the BBC seems to be in Beijing  ::)
« Last Edit: August 24, 2008, 02:46:35 PM by rizla »
Logged

guest

  • Guest
Re: Stayed at a Best Western since 2007?
« Reply #3 on: August 24, 2008, 01:32:00 PM »

I've confirmed this myself by making a couple of calls. It is the entire European database which was compromised. This includes the UK.
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33930
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Stayed at a Best Western since 2007?
« Reply #4 on: August 24, 2008, 07:12:02 PM »

 :(
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

UncleUB

  • Helpful
  • Senior Kitizen
  • *
  • Posts: 29544
Logged

guest

  • Guest
Re: Stayed at a Best Western since 2007?
« Reply #6 on: August 26, 2008, 01:41:44 PM »

BW have said its all nonsense. They also claim that they purge all customer data one week after departure  ::)

Do any of you seriously believe that BW just "purge" all this info? Info that tells them who their customers are, where they stay, how much they spend, what cards they use, etc etc? If so then there's a nice bridge I know..... ;)

Oh and the PCI DSS rubbish would be the same standards that everyone else who's had databases ripped off (T.J. Maxx springs to mind) complies with too. In short its worthless pap :)

Spinning like a top......  :lol:

Press release - http://www.marketwatch.com/news/story/best-western-responds-sunday-herald/story.aspx?guid=%7BA87F9682-AC67-4803-A135-B6ACF42C0956%7D&dist=hppr
« Last Edit: August 29, 2008, 01:19:37 PM by rizla »
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33930
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Stayed at a Best Western since 2007?
« Reply #7 on: September 01, 2008, 07:43:26 AM »

>> Do any of you seriously believe that BW just "purge" all this info?

nope..   :no:
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker