Nearly 70 Percent of Hotel Websites Leak Your Personal Data, Suggests a Symantec Study
Compromised personal information includes full names, email addresses, credit card details and passport numbers of guests.
(Image for representation)
As it turns out, the data that you give to hotels isn't exactly safe. Two out of three hotel websites inadvertently leak guests’ booking details and personal data to third-party sites, including advertisers and analytics companies, according to research released by online security firm Symantec Corp. The study, which looked at more than 1,500 hotel websites in 54 countries that ranged from two-star to five-star properties, comes several months after Marriott International disclosed one of the worst data breaches in history.
Symantec said Marriott was not included in the study.
Compromised personal information includes full names, email addresses, credit card details and passport numbers of guests that could be used by cybercriminals who are increasingly interested in the movements of influential business professionals and government employees, Symantec said. “While it’s no secret that advertisers are tracking users’ browsing habits, in this case, the information shared could allow these third-party services to log into a reservation, view personal details and even cancel the booking altogether,” said Candid Wueest, the primary researcher on the study.
The research showed compromises usually occur when a hotel site sends confirmation emails with a link that has direct booking information. The reference code attached to the link could be shared with more than 30 different service providers, including social networks, search engines and advertising and analytics services. Wueest said 25 percent of data privacy officers at the affected hotel sites did not reply to Symantec within six weeks when notified of the issue, and those who did took an average of 10 days to respond. “Some admitted that they are still updating their systems to be fully GDPR-compliant,” Wueest said, referring to Europe’s new privacy law, or the General Data Protection Regulation, which took effect about a year ago and has strict guidelines on how organizations should deal with data leakage.
Get the best of News18 delivered to your inbox - subscribe to News18 Daybreak. Follow News18.com on Twitter, Instagram, Facebook, TikTok and on YouTube, and stay in the know with what's happening in the world around you – in real time.
Subscribe to Moneycontrol Pro and gain access to curated markets data, trading recommendations, equity analysis, investment ideas, insights from market gurus and much more. Get Moneycontrol PRO for 1 year at price of 3 months. Use code FREEDOM.
Recommended For You
- Will You Have to Link Your Aadhaar With Facebook, WhatsApp And Twitter Accounts?
- Nick Jonas Signalling I Love You to Priyanka Chopra is the Gold Standard for Romance
- Nine Nurses Who Went Viral for Being Pregnant at the Same Time Have Now Given Birth
- Ashes 2019: Steve Waugh Wowed by Deceptive Archer's 'X-factor'
- Dwayne The Rock Johnson Ties the Knot With Laura Hashian in Secret Hawaiian Wedding, See Pics