REPORT FROM THE U.S.—The U.S. Secret Service has identified another potential chink in the hotel industry’s IT infrastructure armor: the hotel business center.
In a non-public advisory issued to companies in the hospitality industry on 10 July, the Secret Service and the Department of Homeland Security’s National Cybersecurity and Communications Integration Center warned a task force in Texas recently arrested suspects who had compromised computers within several major hotel business centers in the Dallas/Fort Worth areas.
“In some cases, the suspects used stolen credit cards to register as guests of the hotels; the actors would then access publicly available computers in the hotel business center, log into their Gmail accounts and execute malicious key logging software,” the advisory, which was obtained by Krebs on Security, reads.
“The keylogger malware captured the keys struck by other hotel guests that used the business center computers, subsequently sending the information via email to the malicious actors’ email accounts,” the warning continued. “The suspects were able to obtain large amounts of information, including other guests’ personally identifiable information, log-in credentials to bank, retirement and personal webmail accounts, as well as other sensitive data flowing through the business center’s computers.”
The advisory is on the radar of several major hotel chains. Hilton Worldwide Holdings, for instance, issued the following statement:
“Hilton Worldwide is strongly committed to the protection and privacy of our guests’ personal information. Currently we are unaware of any cyber-attacks at our hotels in the Dallas/Ft. Worth area. Should we learn of a database breach at Hilton Worldwide, we will fully cooperate with law enforcement agencies and immediately notify those guests who may have been impacted to work toward resolution.”
The advisory lists several basic recommendations for hotels to help secure public computers, such as limiting guest accounts to non-administrator accounts that do not have the ability to install or uninstall programs.
“This is a classic example of the current hotel balancing act between being hospitable (‘Of course you can use our business center computer!’) and providing data security (‘Don’t even think about touching it!’),” Jon Inge, head of technology consultancy Jon Inge & Associates, wrote in an email.
The end of hotel business centers?
The nature of traditional hotel business centers makes them inherently vulnerable to attack because they give users physical access to the computers, sources said.
That’s a huge no-no, according to Microsoft’s TechNet blog’s “10 immutable laws of security.” No. 3 on the list: “If a bad guy has unrestricted physical access to your computer, it’s not your computer anymore.”
“Key loggers used to be on USB drives that plugged into the computer, which is why many hotels blocked off the USB ports on business center systems,” Inge said. “Now they’re in software, and as long as you have a way to physically load them on the PC, they’re undetectable by guests. …
“I don’t see how hotels can continue to allow guests to insert physical devices onto guest-access computers, whether they be USB drives or CD disks.”
Deb Lambert, e-business director for Vantage Hospitality Group, believes the vulnerability is a “serious threat,” she wrote in an email. That’s why she never uses business centers when she travels. “I travel fully loaded with all the equipment I need.”
It’s not just computers in business centers that are at risk, she added. So too are tablets and desktops hoteliers have begun to provide in the lobby and other public areas.
Lambert said the hotel business center will evolve to accommodate such threats.
“I think the traditional business center will morph into a technology center, with a business center Wi-Fi setup with wireless printers or a boarding pass kiosk. Since hotels already have to worry about PCI Compliance, having separate Wi-Fi for the business center is a no-brainer,” she said.
The Kinzie Hotel in Chicago, for one, is moving in that direction. While the property still has a traditional business center off the lobby, it’s undergone an extensive renovation to create a more robust “executive workspace” in each guestroom. Upgrades include the ability to securely send documents from the room to the business center for printing, which requires the user to physically enter a private access code, said Jose Angulo, the hotel’s director of sales and marketing.
Short of large IT-related capital expenditures, hoteliers should at least be transparent, Lambert said.
“Those hotels that continue to offer access to PCs should post security warnings to their guests,” she said.