Skip to content
Thursday 13 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,833.15
-0.10%
DAX
26,331.07
0.00%
CAC 40
8,674.94
0.00%
STOXX 50
6,533.99
0.00%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Wednesday 10 April 2019 3:04 pm  |  Updated:  Monday 03 June 2019 1:32 am

Two-thirds of hotel websites leave guests’ personal data exposed to hackers

By: James Warrington

Add as a preferred source on Google

Two-thirds of hotel websites inadvertently leak guests’ personal data to third-party companies and leave customers vulnerable to hackers, a new report has revealed.

Research by cyber security firm Symantec has found the majority of hotels use booking systems that could allow scammers to access information such as mobile phone numbers and passport details.

Read more: Government urges businesses to ramp up cyber security

The report found confirmation emails sent to customers often contain an unsecured direct link to their booking, meaning anyone on the same network could intercept the email and modify or cancel their reservation.

But it could also allow hackers to harvest personal data for use in future scams or extortion.

In addition, the flawed security means third-party sites such as advertisers and analytics companies could view the information.

The security lapses are in breach of the EU’s GDPR laws, which state firms must protect the personal data of customers.

“The fact that this issue exists, despite the GDPR coming into effect in Europe almost one year ago, suggests that the GDPR’s implementation has not completely addressed how organisations respond to data leakage,” said Candid Wueest, principal threat researcher at Symantec.

According to the report, poor security on some websites could enable attackers to carry out so-called brute forcing, allowing them to gain access to multiple bookings.

Through this technique, cyber criminals would be able to work out the booking reference number and log in of any customers just with knowledge of their surname or email address.

Wueest told Morning Wire the flaws showed firms still do not fully understand how to comply with data protection laws, and warned they could face fines if caught.

The hospitality sector has been hit with several high-profile cyber security breaches in recent months, with major attacks targeting guests at chains such as Marriott and Hilton.

Read more: A third of small businesses have no cyber security strategy

“Rules regarding GDPR and the security of guests’ information is obviously a priority,” said Kate Nicholls, chief executive of UK Hospitality.

“Customers staying in UK hotels need to feel confident that their details are not going anywhere they shouldn’t. We have not had any feedback from our hotel members that there is an acute problem, but we will be in touch with all our members to provide support and share best practice.”

 

 

 

 

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Related Topics

  • Data protection

Trending Articles

  • Five-star Mayfair hotel hit with HMRC winding-up petition

  • It’s not just Jason Arday, most of sociology is a scam

  • IT consultant ordered to pay £50,000 after being accused of stealing Soho House members’ personal details

  • As it happened: FTSE 100 falls as Iran and US clash over Strait of Hormuz; Oil stockpiles ‘rapidly depleting’

  • As it happened: Stocks jittery as oil nears $90; Trump ‘semi-negotiating’ with Iran

More from Morning Wire

  • Accertify and Liminal Release First Empirical Study Proving Fraud-Cyber Convergence Works – and Defining How to Do It Right

    Business Wire
  • U.K. Firms Make Cyber Resilience Measurable

    Business Wire
  • New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It

    Business Wire
  • AI gold rush leaves accountancy firms exposed to costly cyberattacks

    AI
    Two tablets displaying code and a cyber warning symbol, with blurry blue and pink background numbers
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • Beware the AI holiday let

    Opinion
    Holiday let house with slate roof, dormer windows, and a TO LET sign in the foreground.
  • Quality Pays: New Vrbo Research Finds Travelers Will Spend More on Vacation Rentals They Trust

    Business Wire
  • Wasabi and Megaport Partner to Advance the Next Generation of AI and Cloud Infrastructure

    Business Wire
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook