Hyatt Hotels suffer second credit card breach in as many years
Malware discovered lurking in 41 Hyatt hotels
The Hyatt Hotel chain has suffered a second breach of credit card data in under two years, with around 41 hotels globally are said to be affected.
According to a statement issued by the company, it discovered signs of, and then resolved unauthorised access to payment card information from cards manually entered or swiped at the front desk of certain Hyatt-managed locations between 18 March and 2 July this year.
According to Chuck Floyd, global president of operations at Hyatt Hotels Corporation, when the hotel discovered the breach it launched a comprehensive investigation to understand what happened and how this occurred. This included engaging third-party experts, payment card networks and authorities.
"Based on our investigation, we understand that such unauthorised access to card data was caused by an insertion of malicious software code from a third party onto certain hotel IT systems," he said.
Floyd added that its measures and additional layers of defence implemented over time helped to identify and resolve the issue. He said that there was no indication that information beyond that gained from payment cards cardholder name, card number, expiration date and internal verification code was involved.
"As a result of implemented measures designed to prevent this from happening in the future, guests can feel confident using payment cards at Hyatt hotels worldwide," he said.
Floyd said that it was estimated that the incident affected a small percentage of payment cards used by guests who visited the group of affected Hyatt hotels during the at-risk time period. He added the available information and data does not allow Hyatt to identify each specific payment card that may have been affected.
"It's important to Hyatt that we notify guests and provide helpful information about steps they can take, and we have directly contacted all guests for whom we have appropriate contact information that checked in to an affected hotel during the at-risk dates. As always, the primary step customers can take is to review their payment card account statements closely and report any unauthorised charges to their card issuer immediately," said Floyd.
This is not the first time that Hyatt customers have been the victim of a credit card breach. In August last year, customers at 20 US hotels may have had their credit card details exposed to hackers after malware was discovered on the properties' point-of-sale (POS) systems.
The hotels are run by a hotel management business, HEI Hotels and Resorts, but operate under big-name brands like Marriott, Hyatt and InterContinental Hotels Group (IHG).
A list of affected hotels and respective at-risk dates is available here.
What you need to know about migrating to SAP S/4HANA
Factors to assess how and when to begin migrationDownload now
Your enterprise cloud solutions guide
Infrastructure designed to meet your company's IT needs for next-generation cloud applicationsDownload now
Testing for compliance just became easier
How you can use technology to ensure compliance in your organisationDownload now
Best practices for implementing security awareness training
How to develop a security awareness programme that will actually change behaviourDownload now