Hilton Worldwide Holdings, a hotel group, revealed that credit card information was stolen by cybercriminals from a few of its point-of-sale systems.
Executive vice president of Hilton Global Brands Jim Holthouser claims that malware compromised PoS systems, enabling hackers to obtain client information such as credit card numbers, expiration dates, security codes, and names of credit card holders.
In certain point-of-sale systems, unauthorised malware that targeted credit card information has been found and removed by Hilton Worldwide.
It was discovered that the data breach did not expose the customer's addresses or personal identification numbers.
Source: https://securityaffairs.com/42265/cyber-crime/hilton-data-breach.html
TPRM report: https://scoringcyber.rankiteo.com/company/hilton
"id": "hil1733261023",
"linkid": "hilton",
"type": "Breach",
"date": "11/2015",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Hospitality',
'name': 'Hilton Worldwide Holdings',
'type': 'Hotel Group'}],
'attack_vector': 'Malware',
'data_breach': {'data_exfiltration': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Credit card numbers',
'Expiration dates',
'Security codes',
'Names of credit card holders']},
'description': 'Credit card information was stolen by cybercriminals from a '
"few of Hilton Worldwide Holdings' point-of-sale systems due "
'to malware.',
'impact': {'data_compromised': ['Credit card numbers',
'Expiration dates',
'Security codes',
'Names of credit card holders'],
'payment_information_risk': True,
'systems_affected': 'Point-of-Sale Systems'},
'initial_access_broker': {'entry_point': 'Point-of-Sale Systems'},
'motivation': 'Financial Gain',
'post_incident_analysis': {'corrective_actions': 'Malware removed from '
'point-of-sale systems',
'root_causes': 'Malware compromised PoS systems'},
'response': {'containment_measures': 'Malware removed from point-of-sale '
'systems'},
'threat_actor': 'Cybercriminals',
'title': 'Hilton Worldwide Credit Card Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Point-of-Sale Systems'}