Site navigation

InterContinental Hotels Group Hack | What Happened?

David Paul

,

InterContinental Hotels Group
It’s emerged that hackers targeted the global hotel chain “for fun” in a recent cyber-attack.

Global InterContinental Hotels Group (IHG) recently became another high-profile victim of a malicious cyber-attack which targeted its booking systems.

Two hackers, who go by the name TeaPea and claim to be a couple from Vietnam, accessed the organisation’s databases through an easily bypassed, weak password, Qwerty1234.

What happened?

Hackers gained access to internal IT network by tricking an employee into downloading software through a malicious email attachment.

They added that they accessed the most sensitive parts of IHG’s computer system after finding login details for the company’s internal password vault.

Such a vault is available to all employees, meaning up to 200,000 staff has access.

In a statement to the BBC, the pair claimed they had carried out the attack, which has had implications from the hotel giant’s locations “for fun”.

Files appear to have been irreversibly deleted, and the pair appear to be unphased and show little guilt for their actions.

One of the hackers said over Telegram: “Our attack was originally planned to be a ransomware, but the company’s IT team kept isolating servers before we had a chance to deploy it, so we thought to have some funny [sic]. We did a wiper attack instead.”

How did the hotel chain respond?

On the 6th of September, the firm released a statement stating that is had begun implementing “response plans,” and was “notifying relevant regulatory authorities”.

“InterContinental Hotels Group PLC (IHG or the Company) reports that parts of the Company’s technology systems have been subject to unauthorised activity. IHG’s booking channels and other applications have been significantly disrupted since yesterday, and this is ongoing.”

The statement continued: “IHG is working to fully restore all systems as soon as possible and to assess the nature, extent, and impact of the incident. We will be supporting hotel owners and operators as part of our response to the ongoing service disruption. IHG’s hotels are still able to operate and to take reservations directly.”

What can be learned?

In response to the news, Jordan Schroeder, managing CISO at Barrier Networks, commented: “In this instance, it fortunately looks like IHG was able to prevent the attackers from deploying ransomware, but in retaliation they deleted the data they had accessed, putting the hotel chain in a no-win situation.

“This goes to show that resilience should always the priority. Stopping attackers getting into systems must be the focus, because once they are in, organisations then have very little control over what will happen to their data next.

“Account monitoring should be in place to identify compromised accounts. Additionally, being able to recover from unexpected events quickly and easily must also be a focus. The stakes are high and there are simply no guarantees on the path an attacker will take or what they will end up doing.”

The attack could have huger implications for IHG, a UK-based company but runs around 6,000 global hotels under the Regent and Holiday Inn brands, as well as Crowne Plaza.


Recommended


Schroeder continued: “When it comes to defences, these must include good password practices, but using a password that is Qwerty1234 is not an example of this. Unfortunately, this password keeps showing up on “most-used passwords” lists.

“Instead implement strong, unique passwords, implement MFA, use Privileged Access Management (PAM) to protect key accounts, deploy layered security to prevent lateral movement, and train employees regularly on phishing and cybercrime.”

The InterContinental Hotels Group attack is the latest in a string of high-profile cyber-related incidents on major global organisations over the past few weeks.

Major US carrier American Airlines has recently announced a major breach of its systems due to the compromising of employee emails.

The airline notified customers of the breach after attackers compromised the accounts and gained access to sensitive personal information.

In notification letters sent on the 16th of September, the airline explains that it has no evidence that the exposed data was misused.

Image credit: LED Depot.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data