IGMPI facebook Global Hotel Chain Confirms Breach of Loyalty Accounts
IGMPI Logo
Faculty of Cybersecurity Technology

(An Autonomous Body Recognized by Ministry of Commerce & Industry, Government of India)

Competency based placement focussed Education | Training | Research | Consultancy

18001031071 (Toll Free), +91 11 26512850
Regular | Part-time (Online Live Classes) Modes
Global Hotel Chain Confirms Breach of Loyalty Accounts

Global Hotel Chain Confirms Breach of Loyalty Accounts

A well-known international hotel group began notifying customers this week after detecting unauthorized access to a portion of its loyalty program accounts. Investigators believe attackers obtained usernames and passwords from earlier, unrelated data breaches and then launched automated credential-stuffing attacks against the hotel’s login portal. Once inside, criminals redeemed reward points, viewed limited personal details, and attempted to link accounts to fraudulent payment cards. In response, the company forced password resets, enabled mandatory multi-factor authentication in high-risk regions, and introduced additional anomaly checks on redemptions. The incident underscores how even when a company itself is not directly breached, reused credentials can still expose customers and brands to reputational harm.

01-12-2025