when IHG hack: 'Vindictive' couple deleted hotel chain data for fun

Hackers have told the BBC they meted out a harmful cyber-attack against vacation hostelry owner worldwide Hotels cluster (IHG) "for fun".

Describing themselves as a few from Vietnam, they assert they 1st tried a ransomware attack, then deleted giant amounts of information once they were frustrated.

They accessed the FTSE a hundred firm's databases due to Associate in Nursing simply found and weak positive identification, Qwerty1234.

Professional says the case highlights the vindictive facet of criminal hackers.

UK-based IHG operates half dozen,000 hotels round the world, as well as the vacation hostelry, Crowne Plaza and Regent brands.

On weekday last week, customers according widespread issues with booking and arrival.

For 24 hours IHG passed through complaints on social media by language that the corporate was "undergoing system maintenance".

Then on the weekday afternoon it told investors that it had been hacked.

"Booking channels and alternative applications are considerably discontinuous since yesterday," it aforesaid in a political candidate notice lodged with the London stock market.

vacation hostelry hotels hit by cyber-attack
vacation hostelry hotels hit by payment hack

The hackers, business themselves TeaPea, contacted the BBC on the encrypted electronic messaging app, Telegram, providing screenshots as proof that they'd meted out the hack.

The images, that IHG has confirmed area unit real, show they gained access to the company's internal Outlook emails, Microsoft groups chats and server directories.

"Our attack was originally planned to be a ransomware however the company's IT team unbroken analytic servers before we tend to had an opportunity to deploy it, thus we tend to thought to possess some funny [sic]. we tend to did a wiper attack instead," one in every of the hackers aforesaid.

A wiper attack may be a type of cyber-attack that irreversibly destroys information, documents and files.

Cyber-security specialist Rik Ferguson, vice-president of security at Forescout, aforesaid the incident was a cautionary tale as, although the company's IT team at first found some way to fend them off, the hackers were still able to realize some way to visit harm.

"The hackers' modification of manoeuvre appears born out of vindictive frustration," he said. "They could not build cash in order that they lashed out, which fully betrays the very fact that we tend to don't seem to be talking concerning 'professional' cybercriminals here."

IHG says customer-facing systems area unit returning to traditional however that services might stay intermittent.

The hackers area unit showing no sorrow concerning the disruption they need caused the corporate and its customers.

"We do not feel guilty, really. we tend to like better to have a legal job here in Vietnam however the wage is average $300 per month. i am certain our hack will not hurt the corporate tons."

The hackers say no client information was purloined however they are doing have some company information, as well as email records.

TeaPea say they gained access to IHG's internal IT network by tricking Associate in Nursing worker into downloading a malicious piece of computer code through a booby-trapped email attachment.

They additionally had to bypass an extra security prompt message sent to the worker's devices as a part of a two-factor authentication system.

The criminals then say they accessed the foremost sensitive components of IHG's ADP system once finding login details for the company's internal positive identification vault.

"The username and positive identification to the vault was out there to any or all workers, so 200,000 employees might see. and also the positive identification was extraordinarily weak," they told the BBC.

Surprisingly, the positive identification was Qwerty1234, that often seems on lists of most ordinarily used passwords worldwide.

"Sensitive information ought to solely be out there to workers WHO would like access thereto information to try and do their job, and that they ought to have the minimum level of access [needed] to use that information," aforesaid adult male Ferguson, once seeing the screenshots.

"Even a extremely advanced positive identification is simply as insecure as a straightforward one if it's left exposed."

An IHG spokesperson controversial that the positive identification vault details weren't secure, language that the offender had to evade "multiple layers of security", however wouldn't shed light on concerning the additional security.

"IHG employs a defence-in-depth strategy to info security that leverages several trendy security solutions," she extra.

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author

video Editor, writer