Hospitality giant H-Hotels recently suffered a cyber attack that disrupted digital communications and forced it to disconnect all IT systems from the Internet.
Founded in 1969, H-Hotels operates in 50 locations across Germany, Austria, and Switzerland under the brand name ’H-Hotels’ and sub-brands Hyperion, H4 Hotels, H2 Hotels, H + Hotels, H.ostels, and H.omes.
In a recent
notification posted on its website, the company confirmed that on December 11, it suffered a cyber attack that involved unauthorised parties gaining access to its internal network and disrupting its digital communication.
As soon as the company’s IT security systems identified the security incident, its IT systems were immediately shut down and disconnected from the internet to prevent hackers from accessing them.
While the hotel chain is currently unavailable by email, it is still accepting bookings and is running daily operations as usual. “Customers are recommended to contact the desired or already booked a hotel by telephone if they wish to be contacted,” the notice read.
“H-Hotels.com immediately informed the responsible investigative authorities and filed a criminal complaint. IT forensic experts are currently examining all affected IT systems in close cooperation with the investigating authorities in order to secure traces for further investigations.
“This work will take a few days. All systems are then cleaned and all data is finally checked in order to be able to rule out a continuation of the cyber attack or a new cyber attack,” the hotel chain added.
H-Hotels further confirmed that, as of now, it has no evidence of any sensitive personal data of its customer being compromised, but if further investigation reveals any such data breach, affected individuals will be contacted by the company.
The Play ransomware gang has claimed responsibility for the cyber attack on H-Hotels and has listed the company as its latest victim on its data leak site. While the threat actors are yet to publish sample data collected from the cyber attack, they claim to have stolen private and personal data, including client documents, passports, IDs, and more.
Commenting on the news, Mark Lamb, CEO of HighGround.io, said, “This incident shows just how calculated criminals can be with their timings of attacks. The hotel will now be scrambling to get systems back up and running before customer bookings are disrupted and its reputation suffers irreparable damage.
“It is unclear whether the claims from the Play criminal gang are genuine, so H-Hotels must investigate this urgently as ID cards and passports are the kinds of documents no one ever wants to have floating about on the dark web, particularly as changing them can be a big inconvenience during the holiday season. This incident once again highlights that the prevention of attacks should always be the primary goal, as the remediation of security incidents can often take months and be very costly.
“This means training staff on hacking techniques and ensuring businesses employ good cyber hygiene practices, like patching vulnerabilities and keeping software up to date. It is also vital that businesses have an easy way to assess their cybersecurity posture, so they can quickly identify weaknesses that could be maliciously exploited. This will help close attacker loopholes and make cybersecurity more accessible and understandable for businesses with smaller cybersecurity teams and budgets,” Lamb added.