Hyatt Hotels suffer second credit card breach in as many years

Malware discovered lurking in 41 Hyatt hotels

Data breach

The Hyatt Hotel chain has suffered a second breach of credit card data in under two years, with around 41 hotels globally are said to be affected.

According to a statement issued by the company, it discovered signs of, and then resolved unauthorised access to payment card information from cards manually entered or swiped at the front desk of certain Hyatt-managed locations between 18 March and 2 July this year. 

According to Chuck Floyd, global president of operations at Hyatt Hotels Corporation, when the hotel discovered the breach it launched a comprehensive investigation to understand what happened and how this occurred. This included engaging third-party experts, payment card networks and authorities. 

"Based on our investigation, we understand that such unauthorised access to card data was caused by an insertion of malicious software code from a third party onto certain hotel IT systems," he said.

Advertisement - Article continues below
Advertisement - Article continues below

Floyd added that its measures and additional layers of defence implemented over time helped to identify and resolve the issue. He said that there was no indication that information beyond that gained from payment cards cardholder name, card number, expiration date and internal verification code was involved.

"As a result of implemented measures designed to prevent this from happening in the future, guests can feel confident using payment cards at Hyatt hotels worldwide," he said.

Floyd said that it was estimated that the incident affected a small percentage of payment cards used by guests who visited the group of affected Hyatt hotels during the at-risk time period. He added the available information and data does not allow Hyatt to identify each specific payment card that may have been affected. 

"It's important to Hyatt that we notify guests and provide helpful information about steps they can take, and we have directly contacted all guests for whom we have appropriate contact information that checked in to an affected hotel during the at-risk dates. As always, the primary step customers can take is to review their payment card account statements closely and report any unauthorised charges to their card issuer immediately," said Floyd.

This is not the first time that Hyatt customers have been the victim of a credit card breach. In August last year, customers at 20 US hotels may have had their credit card details exposed to hackers after malware was discovered on the properties' point-of-sale (POS) systems.

The hotels are run by a hotel management business, HEI Hotels and Resorts, but operate under big-name brands like Marriott, Hyatt and InterContinental Hotels Group (IHG).

Advertisement - Article continues below

 A list of affected hotels and respective at-risk dates is available here.

Featured Resources

Transform the operator experience with enhanced automation & analytics

Bring networking into the digital era

Download now

Artificially intelligent data centres

How the C-Suite is embracing continuous change to drive value

Download now

Deliver secure automated multicloud for containers with Red Hat and Juniper

Learn how to get started with the multicloud enabler from Red Hat and Juniper

Download now

Get the best out of your workforce

7 steps to unleashing their true potential with robotic process automation

Download now



Hackers abuse LinkedIn DMs to plant malware

25 Feb 2019

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Best antivirus for Windows 10

3 Sep 2019

Best free malware removal tools 2019

8 Mar 2019

Most Popular

Microsoft Windows

This exploit could give users free Windows 7 updates beyond 2020

9 Dec 2019

Patch issued for critical Windows bug

11 Dec 2019
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
big data

Google reveals UK’s most searched for terms in 2019

11 Dec 2019