Hyatt Hotels suffer second credit card breach in as many years

Data breach

The Hyatt Hotel chain has suffered a second breach of credit card data in under two years, with around 41 hotels globally are said to be affected.

According to a statement issued by the company, it discovered signs of, and then resolved unauthorised access to payment card information from cards manually entered or swiped at the front desk of certain Hyatt-managed locations between 18 March and 2 July this year.

According to Chuck Floyd, global president of operations at Hyatt Hotels Corporation, when the hotel discovered the breach it launched a comprehensive investigation to understand what happened and how this occurred. This included engaging third-party experts, payment card networks and authorities.

"Based on our investigation, we understand that such unauthorised access to card data was caused by an insertion of malicious software code from a third party onto certain hotel IT systems," he said.

Floyd added that its measures and additional layers of defence implemented over time helped to identify and resolve the issue. He said that there was no indication that information beyond that gained from payment cards cardholder name, card number, expiration date and internal verification code was involved.

"As a result of implemented measures designed to prevent this from happening in the future, guests can feel confident using payment cards at Hyatt hotels worldwide," he said.

Floyd said that it was estimated that the incident affected a small percentage of payment cards used by guests who visited the group of affected Hyatt hotels during the at-risk time period. He added the available information and data does not allow Hyatt to identify each specific payment card that may have been affected.

"It's important to Hyatt that we notify guests and provide helpful information about steps they can take, and we have directly contacted all guests for whom we have appropriate contact information that checked in to an affected hotel during the at-risk dates. As always, the primary step customers can take is to review their payment card account statements closely and report any unauthorised charges to their card issuer immediately," said Floyd.

This is not the first time that Hyatt customers have been the victim of a credit card breach. In August last year, customers at 20 US hotels may have had their credit card details exposed to hackers after malware was discovered on the properties' point-of-sale (POS) systems.

The hotels are run by a hotel management business, HEI Hotels and Resorts, but operate under big-name brands like Marriott, Hyatt and InterContinental Hotels Group (IHG).

A list of affected hotels and respective at-risk dates is available here.

Rene Millman

Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.