Hilton Hotels Loyalty Program Data Breached, Info of 3.7M Users for Sale
thecyberexpress.com
thecyberexpress.com
Hilton has over a million hotel rooms, 3.7M reservations is nothing.
Most likely this data comes from some OTA that was breached.
Edit: I downloaded the actual dump. It only contains 775k unique reservations from approx 450k unique people, the other 3M are just duplicates. All of the reservations are in the US, for only around 35 different properties.
The only PII contained in the dump are Hilton Honors IDs and names, there are no addresses despite the article claiming otherwise.
What do you mean here? I take OTA to mean "over the air," but I'm struggling to see the connection to this breach. Were reservations being transmitted by radio/satellite?
A third party booking site like travel.com or Priceline.com used to book hotels and airlines instead of booking directly. I never use third party sites.
I'd be worried about being locked out at some point; I get asked to confirm I'm me via phone/SMS fairly regularly.
On the other hand, I really don’t have a problem giving my real number to hotels, airlines or any other business that I deal with regularly.
At franchised hotels in the US, which is almost all chain hotels, the employees at the front desk do not have the ability to email you, or even know your email address. The phone number is often the only way to reach you.
Hilton does have the chat app, but I do not think it works for hotels trying to reach customers with time sensitive information.
I am not worried about a 1% edge case
When I worked, we used to have to often change room types from rooms with 1 queen bed to a room with 2 full XL beds (full XL is 6 inches narrower than a queen).
Of course, technically, this would modify a guest’s reservation and give them an inferior bed than the one they reserved, so we would go down the list of people who had reserved a room with 1 queen bed and ask if they were willing to change to a room with 2 full XL size beds, and as a thank you, offered a few thousand points.
Obviously, all the single business travelers had no problem accepting a couple extra thousand points for a bed that was 6 less inches wide, but if they did not have a good phone number on the reservation, they were not offered.
Much like the person that has their 2FA app on their phone, and their backup keys burn down in their house and then is suddenly on HN begging for Google support to help them because they are in a catch-22 situation no one cares about the edge cases until they are being crushed under one.
Also a 1% failure rate is off the charts when you're talking about serving millions.
/s
uh oh!
I get called by hotels all the time. But maybe because I stay in s a lot of "high touch" properties that pride themselves on providing exemplary service.
You're not going to get called by a Holiday Inn Express. But you certainly will get called when you're spending $800+ a night.
The other half of the year, we are staying in our own “Condotel”. They are individually owned condos that are rented out and managed like a hotel when we aren’t there.
When we first came to our condo in January, everyday they would knock on my door at the worse time.
The last thing I want in either context - whether I’m on a business trip, “nomadding “, at “home”, or vacationing is “high touch”.
I want to check in digitally, use my digital key and check out digitally. I put “Do not disturb” on my door the entire time.
That is not really what high-touch means in the context of luxury hotels, $1000+/night places will generally do their best to not disturb you. Instead it's things like coordinating housekeeping based on reservations the concierge has made for you, or perhaps just quietly stocking your room with a beverage you seemed to particularly enjoy by the pool.
>I want to check in digitally, use my digital key and check out digitally. I put “Do not disturb” on my door the entire time.
I tend to prefer in-room check-in, a very common practice in luxury hotels. A front desk staffer walks you to the room, giving you an easy opportunity to raise any issues or ask any questions you might have regarding the room.
And in any case, digital check-in is unfortunately legally difficult in many jurisdictions which require hotels to scan your passport.
Regarding the phone calls, most people at this level use travel agents so the hotels won't have the client's direct contact information anyway. It's the travel agents job to communicate any preferences you might have regarding the stay.
If you're booking directly, it's common and useful for the hotel to reach out to you regarding your preferences and to see if you might need them to arrange something like airport VIP services or transfers. Nobody will be upset if you've provided a fake number and the hotel can't reach you, your reservation won't be cancelled.
Than you for proving my point.
My wife and I digital nomad 6.5 months out of the year
I find the tech bubble's "digital nomad" boasting humorous.
I did that from 2006 to 2011. Round-robined between Japan, Singapore, Hong Kong, and a few places in the U.S. It was called "working."
And it wasn't even new when I did it. My father did it in the 80's.
> I stay in a lot of hotels. I’ve never once been called.
I've been called because of a travel issue, once. About a little more than a decade ago, I was scheduled to fly out of an airport that didn't actually end up opening for another several years. I believe the only heads-up notice I got about the change in my itinerary was a phone call about a month before my departure.
I do the same thing as you. But it's worth noting that you don't know that you've never had a problem, since nobody can contact you about one.
I've only had problems that I know of three times. Once when a purchase from Ohio got mangled in shipping and returned to the company. It tried to contact me to let me know there was a delay, and when it couldn't get in touch with me, it put the order on hold. I found out about it when I called a couple of weeks later to ask what happened to my order.
Once when something I ordered from overseas had trouble getting through customs. Again, I had to call to find out what happened.
And once when I made a hotel reservation in Los Angeles. The hotel called to let me know that the upgrade I requested was available, and when it couldn't get me by phone it believed the transaction to be fraudulent and cancelled my reservation.
Is it okay if your primary email, phone number and email address are out there in the wild?
Everyone's is. That ship has sailed.
for those with an email address per-service, it's not true at all - and even when an email is leaked it is trivial to shut that email down.
in the past the guidance was don't re-use your passwords - I posit that the guidance should now be don't re-use your email addresses.
Because this is so obvious I do not consider email per service useful unless you can cheaply create aliases that are not related to your main email, and adding aliases is not and automatic scheme, but instead. You have to do all of them or the entire scheme is useless, and the effort is high enough that I doubt the average person would do this even if we made it easy. Don't forget that you also need to select the right account to send from for each message while you think the place is not evil.
They probably already were out in the wild.
It seems hard to believe but back when people had landlines, just about everybody was listed in the phone book -- name, address, and phone number.
And that address was static, typically discoverable by other means, instead of a digital object that could locate you 24x7 anywhere in the world.
The real risk is that there’s backend integration between multiple systems. It’s a nexus between airline and other systems, and if you are a person with personal security concerns who hasn’t really thought about this scenario, you need to think because you’re compromised.
2015 article as an example: https://www.usatoday.com/story/travel/roadwarriorvoices/2015...
>Under GDPR, the fine would have been $420M
That's not how the GDPR works.