Hilton

Hilton

Hilton Worldwide Holdings, a hotel group, revealed that credit card information was stolen by cybercriminals from a few of its point-of-sale systems.

Executive vice president of Hilton Global Brands Jim Holthouser claims that malware compromised PoS systems, enabling hackers to obtain client information such as credit card numbers, expiration dates, security codes, and names of credit card holders.

In certain point-of-sale systems, unauthorised malware that targeted credit card information has been found and removed by Hilton Worldwide.

It was discovered that the data breach did not expose the customer's addresses or personal identification numbers.

Source: https://securityaffairs.com/42265/cyber-crime/hilton-data-breach.html

TPRM report: https://scoringcyber.rankiteo.com/company/hilton

"id": "hil1733261023",
"linkid": "hilton",
"type": "Breach",
"date": "11/2015",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Hospitality',
                        'name': 'Hilton Worldwide Holdings',
                        'type': 'Hotel Group'}],
 'attack_vector': 'Malware',
 'data_breach': {'data_exfiltration': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Credit card numbers',
                                              'Expiration dates',
                                              'Security codes',
                                              'Names of credit card holders']},
 'description': 'Credit card information was stolen by cybercriminals from a '
                "few of Hilton Worldwide Holdings' point-of-sale systems due "
                'to malware.',
 'impact': {'data_compromised': ['Credit card numbers',
                                 'Expiration dates',
                                 'Security codes',
                                 'Names of credit card holders'],
            'payment_information_risk': True,
            'systems_affected': 'Point-of-Sale Systems'},
 'initial_access_broker': {'entry_point': 'Point-of-Sale Systems'},
 'motivation': 'Financial Gain',
 'post_incident_analysis': {'corrective_actions': 'Malware removed from '
                                                  'point-of-sale systems',
                            'root_causes': 'Malware compromised PoS systems'},
 'response': {'containment_measures': 'Malware removed from point-of-sale '
                                      'systems'},
 'threat_actor': 'Cybercriminals',
 'title': 'Hilton Worldwide Credit Card Data Breach',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Point-of-Sale Systems'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.