Recent hotel data breaches highlight outdated PoS protection

Thursday, 23 Apr, 2015 0

It was déjà vu all over again for hotel management company White Lodging as it announced another data breach earlier this month.  The company eventually came clean, admitting point of sale terminals in 10 hotel bars and restaurants had been infected with malware for at least seven months. All this comes despite White Lodging’s appointment of a third-party security firm to beef up internal systems following an earlier, more comprehensive data breach a year earlier.

Hotels have long been thought of as a soft target for cybercrooks and following the fallout from high profile data breaches, hospitality firms are unsurprisingly reticent in giving away too many details on their front and back office vulnerabilities.  

Yet it is not just the hotel sector that could be paying the price for complacency. A recent report suggests a staggering number of retailers are putting themselves and their customers’ sensitive data at risk due to very fundamental mistakes. Data security firm Trustwave has revealed some shocking statistics which could open the malware floodgates for many small stores, hoteliers and travel agents.

"The big issue is not the latest strain of malware, it’s how the malware is getting on your PoS in the first place," says Trustwave VP of managed testing Charles Henderson.

One damning statistic is the fact that 90% of PoS terminals tested by Trustwave still run the six-digit default password the device came with, even though many of these systems date back to the 1990s.

"They haven’t been tested in the same way that the attackers are testing them. It’s not like the hackers are going to the ends of the earth to get malware on these machines," said Henderson.

Henderson says plugging some of the loopholes is neither expensive, too technical or time consuming.

"Averaged out of the number of PoS terminals deployed, testing isn’t a big investment as you only need to test one of each type".

"The industry hasn’t learned from parallel technologies – routers for example – which are now mostly supplied already secured," said Henderson.

He also urges businesses to use network segmentation to isolate PoS systems to easier detect, and then contain malware attacks.

Prior to the latest malware strike at White Lodging, upscale hotel group Mandarin Oriental was the latest big name in hospitality to suffer a PoS breach.  According to the company, the incursion was "undetectable by all anti-viral systems" leading other security experts to suggest its PoS hardware was outdated and inadequate.

"This breach has once again brought to light concerns around PoS systems, which are often built on antiquated technology," says Andrew Avanessian, executive vice-president of consultancy and technology for security firm Avecto.

"These terminals tend to be legacy systems run on Windows XP for example, which are not patched regularly. Though XP expired last year, there is still a perceived supportability of POS via limited patching until 2016, due to a 10-year license of embedded systems, so a lot of organisations are sticking with it for the next year, despite its risks."



 

profileimage

TravelMole Editorial Team

Editor for TravelMole North America and Asia pacific regions. Ray is a highly experienced (15+ years) skilled journalist and editor predominantly in travel, hospitality and lifestyle working with a huge number of major market-leading brands. He has also cover in-depth news, interviews and features in general business, finance, tech and geopolitical issues for a select few major news outlets and publishers.



Most Read

Vegas’s Billion-Dollar Secrets – What They Don’t Want Tourists to Know

Visit Florida’s New CEO Bryan Griffin Shares His Vision for State Tourism with Graham

Chicago’s Tourism Renaissance: Graham Interviews Kristin Reynolds of Choose Chicago

Graham Talks with Cassandra McCauley of MMGY NextFactor About the Latest Industry Research

Destination International’s Andreas Weissenborn: Research, Advocacy, and Destination Impact

Graham and Don Welsh Discuss the Success of Destinations International’s Annual Conference

Graham and CEO Andre Kiwitz on Ventura Travel’s UK Move and Recruitment for the Role

Brett Laiken and Graham Discuss Florida’s Tourism Momentum and Global Appeal

Graham and Elliot Ferguson on Positioning DC as a Cultural and Inclusive Global Destination

Graham Talks to Fraser Last About His England-to-Ireland Trek for Mental Health Awareness

Kathy Nelson Tells Graham About the Honour of Hosting the World Cup and Kansas City’s Future

Graham McKenzie on Sir Richie Richardson’s Dual Passion for Golf and His Homeland, Antigua
TRAINING & COMPETITION
Skip to toolbar
Clearing CSS/JS assets' cache... Please wait until this notice disappears...
Updating... Please wait...