Ten million customers’ personal data exposed by booking software glitch
Customers of Hotels.com, Booking.com, Expedia and other major booking sites have reportedly had their personal data exposed.
Security experts at Website Planet say data from millions of hotel guests globally were exposed via third-party service Prestige Software which provides automated booking solutions to major travel brands.
It said data was exposed possibly dating back to 2013.
Website Planet says Prestige’s Amazon Web Services (AWS) cloud storage service was misconfigured, which led to data of more than 10 million customers becoming visible and potentially exposed to unauthorised persons.
The individual log files contained personally identifiable information such as names, email addresses, and phone numbers of hotel guests, as well as full cardholder information including number and CVV.
"Cybercriminals could use the exposed PII data and credit card information to commit credit card fraud and steal from people compromised in the breach," the Website Planet report said.
They reported it to AWS and it was fixed within a day.
Website Planet said it couldn’t ascertain if data was accessed by cybercriminals.
"So far, there is no evidence of this happening. However, if it did, there would be enormous implications for the privacy, security and financial wellbeing of those exposed," said researcher Mark Holden.
Written by Ray Montgomery, US Editor
Related News Stories:
TravelMole Editorial Team
Editor for TravelMole North America and Asia pacific regions. Ray is a highly experienced (15+ years) skilled journalist and editor predominantly in travel, hospitality and lifestyle working with a huge number of major market-leading brands. He has also cover in-depth news, interviews and features in general business, finance, tech and geopolitical issues for a select few major news outlets and publishers.
BA pilot dies during layover
Dozens fall ill in P&O Cruises ship outbreak
Turkish Airlines flight in emergency landing after pilot dies
Boy falls to death on cruise ship
Protestors now targeting Amsterdam cruise calls