Skip to content
Sunday 9 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,901.09
+0.31%
DAX
26,319.45
+0.69%
CAC 40
8,714.93
+0.17%
STOXX 50
6,523.86
+0.33%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Wednesday 10 April 2019 3:04 pm  |  Updated:  Monday 03 June 2019 1:32 am

Two-thirds of hotel websites leave guests’ personal data exposed to hackers

By: James Warrington

Add as a preferred source on Google

Two-thirds of hotel websites inadvertently leak guests’ personal data to third-party companies and leave customers vulnerable to hackers, a new report has revealed.

Research by cyber security firm Symantec has found the majority of hotels use booking systems that could allow scammers to access information such as mobile phone numbers and passport details.

Read more: Government urges businesses to ramp up cyber security

The report found confirmation emails sent to customers often contain an unsecured direct link to their booking, meaning anyone on the same network could intercept the email and modify or cancel their reservation.

But it could also allow hackers to harvest personal data for use in future scams or extortion.

In addition, the flawed security means third-party sites such as advertisers and analytics companies could view the information.

The security lapses are in breach of the EU’s GDPR laws, which state firms must protect the personal data of customers.

“The fact that this issue exists, despite the GDPR coming into effect in Europe almost one year ago, suggests that the GDPR’s implementation has not completely addressed how organisations respond to data leakage,” said Candid Wueest, principal threat researcher at Symantec.

According to the report, poor security on some websites could enable attackers to carry out so-called brute forcing, allowing them to gain access to multiple bookings.

Through this technique, cyber criminals would be able to work out the booking reference number and log in of any customers just with knowledge of their surname or email address.

Wueest told Morning Wire the flaws showed firms still do not fully understand how to comply with data protection laws, and warned they could face fines if caught.

The hospitality sector has been hit with several high-profile cyber security breaches in recent months, with major attacks targeting guests at chains such as Marriott and Hilton.

Read more: A third of small businesses have no cyber security strategy

“Rules regarding GDPR and the security of guests’ information is obviously a priority,” said Kate Nicholls, chief executive of UK Hospitality.

“Customers staying in UK hotels need to feel confident that their details are not going anywhere they shouldn’t. We have not had any feedback from our hotel members that there is an acute problem, but we will be in touch with all our members to provide support and share best practice.”

 

 

 

 

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Related Topics

  • Data protection

Trending Articles

  • Burnham facing calls to cut employment red tape as job seekers grow for 41 months

  • Government to inject millions into electric vehicle firms despite mandate backlash

  • Silence Therapeutics to Host Conference Call and Webcast to Discuss Topline Results from Phase 2 SANRECO Trial of Divesiran in Polycythemia Vera

  • Stop burying us in swollen corporate reports, says audit watchdog boss

  • Hargreaves Lansdown orders staff back to office

More from Morning Wire

  • Accertify and Liminal Release First Empirical Study Proving Fraud-Cyber Convergence Works – and Defining How to Do It Right

    Business Wire
  • U.K. Firms Make Cyber Resilience Measurable

    Business Wire
  • New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It

    Business Wire
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • Quality Pays: New Vrbo Research Finds Travelers Will Spend More on Vacation Rentals They Trust

    Business Wire
  • Wasabi and Megaport Partner to Advance the Next Generation of AI and Cloud Infrastructure

    Business Wire
  • Fastmail Launches EU-Hosted Email Infrastructure, Giving Customers Control Over Where Their Data Lives

    Business Wire
  • Trust, stability, resilience and innovation – the cornerstones of 25+ years of cybersecurity leadership

    Partner
    Christiane Hoffmann, a blonde woman in glasses and a black business suit, smiling with arms crossed.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook