Two Out of Three Hotels Accidentally Leak Guests' Personal Data: Symantec

Advertisement
By Reuters | Updated: 10 April 2019 17:57 IST

Two out of three hotel websites inadvertently leak guests' booking details and personal data to third-party sites, including advertisers and analytics companies, according to research released by Symantec on Wednesday.

The study, which looked at more than 1,500 hotel websites in 54 countries that ranged from two-star to five-star properties, comes several months after Marriott International disclosed one of the worst data breaches in history.

Advertisement

Symantec said Marriott was not included in the study.

Compromised personal information includes full names, email addresses, credit card details and passport numbers of guests that could be used by cybercriminals who are increasingly interested in the movements of influential business professionals and government employees, Symantec said.

Advertisement

"While it's no secret that advertisers are tracking users' browsing habits, in this case, the information shared could allow these third-party services to log into a reservation, view personal details and even cancel the booking altogether," said Candid Wueest, the primary researcher on the study.

The research showed compromises usually occur when a hotel site sends confirmation emails with a link that has direct booking information. The reference code attached to the link could be shared with more than 30 different service providers, including social networks, search engines and advertising and analytics services.  

Advertisement

Wueest said 25 percent of data privacy officers at the affected hotel sites did not reply to Symantec within six weeks when notified of the issue, and those who did took an average of 10 days to respond.

"Some admitted that they are still updating their systems to be fully GDPR-compliant," Wueest said, referring to Europe's new privacy law, or the General Data Protection Regulation, which took effect about a year ago and has strict guidelines on how organisations should deal with data leakage.

Advertisement

© Thomson Reuters 2019

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Symantec
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo T5 5G Key Specifications Confirmed Ahead of September 2 India Launch
  2. Samsung Galaxy S26 FE Will Go on Sale in India Soon, Microsites Confirm
  3. Here's Why the Google Pixel 11 Series Will Not Get GrapheneOS
  4. Philips 5G Smartphone Set to Launch in India on This Date
  1. Xiaomi Pad 9 Pro Max Appears on Geekbench With Xring O3 Chip
  2. Philips 5G Smartphone India Launch Date Confirmed: Here’s What We Know
  3. Boltt Reveals Software Update Policy for Ace 5G and Evo Ahead of September 1 Sale
  4. Samsung Galaxy Tab S12 Ultra Allegedly Listed on Geekbench With MediaTek Dimensity 9500 Chipset
  5. NPCI to Soon Allow Users to Port UPI AutoPay Mandates Across Digital Payments Platforms: Report
  6. PhonePe UPI 123Pay Enables UPI Payments Without Internet on Feature Phones in India
  7. Vivo T5 5G Key Specifications Teased; 7,050mAh Battery, Dual Rear Cameras Confirmed
  8. Anthropic’s Claude Closes 85 Percent of AI Safety Gap in Automated Research Test
  9. OpenClaw 2.0 Released as Biggest Update Since Launch; Brings Shared Cloud Sessions, Smarter Automations
  10. Samsung Galaxy S26 FE Set to Go on Sale in India Soon as Multiple Microsites Go Live
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.