Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Ministers open door to phased Heathrow third runway plan

      Heathrow Airport terminal bustling with travelers and staff, showcasing modern architecture and international flight activity

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Concern as gambling black market set for £40m Royal Ascot boost

      GettyImages 2282074836 showing a significant event with key figures in a professional setting, highlighting a major develo...

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      New Mk1 Ford Escort RS makes world debut at London Concours

      Boreham Ford Escort RS car showcasing classic design and performance features at an automotive event.

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Wednesday 10 April 2019 3:04 pm  |  Updated:  Monday 03 June 2019 1:32 am

Two-thirds of hotel websites leave guests’ personal data exposed to hackers

By: James Warrington

Add as a preferred source on Google

Two-thirds of hotel websites inadvertently leak guests’ personal data to third-party companies and leave customers vulnerable to hackers, a new report has revealed.

Research by cyber security firm Symantec has found the majority of hotels use booking systems that could allow scammers to access information such as mobile phone numbers and passport details.

Read more: Government urges businesses to ramp up cyber security

The report found confirmation emails sent to customers often contain an unsecured direct link to their booking, meaning anyone on the same network could intercept the email and modify or cancel their reservation.

But it could also allow hackers to harvest personal data for use in future scams or extortion.

In addition, the flawed security means third-party sites such as advertisers and analytics companies could view the information.

The security lapses are in breach of the EU’s GDPR laws, which state firms must protect the personal data of customers.

“The fact that this issue exists, despite the GDPR coming into effect in Europe almost one year ago, suggests that the GDPR’s implementation has not completely addressed how organisations respond to data leakage,” said Candid Wueest, principal threat researcher at Symantec.

According to the report, poor security on some websites could enable attackers to carry out so-called brute forcing, allowing them to gain access to multiple bookings.

Through this technique, cyber criminals would be able to work out the booking reference number and log in of any customers just with knowledge of their surname or email address.

Wueest told CityAM the flaws showed firms still do not fully understand how to comply with data protection laws, and warned they could face fines if caught.

The hospitality sector has been hit with several high-profile cyber security breaches in recent months, with major attacks targeting guests at chains such as Marriott and Hilton.

Read more: A third of small businesses have no cyber security strategy

“Rules regarding GDPR and the security of guests’ information is obviously a priority,” said Kate Nicholls, chief executive of UK Hospitality.

“Customers staying in UK hotels need to feel confident that their details are not going anywhere they shouldn’t. We have not had any feedback from our hotel members that there is an acute problem, but we will be in touch with all our members to provide support and share best practice.”

 

 

 

 

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Related Topics

  • Data protection

Trending Articles

  • As it happened: Stocks sink after Fed and Bank of England opt for hawkish hold; Oil price tumbles

  • More Big Four blues as Deloitte plans to slash UK audit roles

  • Baillie Gifford in line for Anthropic windfall just months after £3.6bn SpaceX bonanza

  • Revolut pays compensation for waking customer up with push notifications

  • City investors raise alarm on Burnham’s Chancellor pick

More from CityAM

  • Top spook says Russia ‘relentlessly targeting’ UK infrastructure 

    Tech
    GCHQ headquarters at dusk with illuminated windows, showcasing the iconic circular building amidst a vibrant evening sky.
  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • IMF warns AI cyberattacks could trigger global financial crisis

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • Iran and Russia to target Fifa World Cup, threat experts say

    Sport Business
    GettyImages 2277625963 shows a significant event in the news, capturing key figures and moments relevant to current global...
  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • UNPACK ’26 SUMMER TRAVEL TRENDS: DOMESTIC DEMAND RISES AND HOTEL PRICES DROP IN POPULAR INTERNATIONAL DESTINATIONS

    Business Wire
  • Visa data leak piles pressure on Britain’s digital ID push

    Tech
    UK work and study visas have fallen as Labour faces pressure to reduce immigration.
  • UK businesses struggle with triple threat of costs, cyber risks and stagnant growth

    Prof Services
    London office workers collaborating on AI and tech projects, surrounded by computers and digital interfaces in a modern wo...

CityAM Canada — business, markets and opinion for Canadian readers.

Sections

  • Business
  • Markets
  • Tech
  • AI
  • Economics
  • Opinion
  • Cities

Company

  • About
  • Contact

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 CityAM Canada. All rights reserved.
Terms · Privacy · Cookies