Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - You want the Geek? You can't handle the Geek!

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » June 2012 » Wyndham Hotels fined over data breach

Wyndham Hotels fined over data breach


Contributed by: Email on 06/26/2012 02:00 PM [ comments Comments ]


The U.S. Federal Trade Commission has fined Wyndham Hotels for a string of data breaches that resulted in information on hundreds of thousands of customers being lost to cyber criminals.

An FTC complaint, filed on June 26, 2012, asks for "permanent injunctive relief" against Wyndham for failing to maintain what the FTC calls "reasonable security" necessary to keep intruders from compromising the network of the hotel chain. Wyndham's failure to protect its IT network laid the groundwork for a series of three data breaches in which cyber criminals based in Russia stole financial information later used to generate $10.6 million in fraudulent purchases. A Phoenix, Arizona, data center used by Wyndham was the source of the breach, the FTC said.

The complaint describes an epic failure on the part of Wyndham. It alleges that Wyndham Worldwide failed to adequately protect a property management system that was used to manage some 7,000 hotels under the Wyndham Hotels and Resorts under the Days Inn, Ramada and Super 8 brands. Among other things, the Wyndham is alleged to have used default administrative user names and passwords on servers that connected to the Hotels and Resorts network. Also, Wyndham Worldwide stored customer credit card data in plain text, and failed to adequately segregate the property management system from the company's corporate intranet and the public Internet.

The result was a string of security breaches between April 2008 and January 2010 and the theft of customer data.

Beginning in April, 2008, hackers were able to hop scotch from a single Wyndham Hotel's network to the entire Hotels and Resorts network through the company's central property management system. Using a brute force attack, the hackers compromised an administrative account on Hotels and Resorts network. Wyndham, the complaint alleges, failed to notice the intrusion attempt, despite the fact that the hackers guessing resulted in more than 200 administrative accounts getting locked out in the process. Among other things, the company lacked an adequate inventory of its IT assets and was thus failed to correlate the failed login attempts to just two computers in the company's Phoenix data center.

The first attack went undetected for four months, the FTC complaint alleges. In the end, the property management system servers of 41 Wyndham-branded hotels were involved in the breach and payment information on 500,000 accounts was compromised. Much of that information was exported to a server on a domain registered in Russia.





« Daily Reviews Summary 06/26/12 (32 Reviews) @ NT Compatible · Wyndham Hotels fined over data breach · Jealous husband ate wife's lip 'on impulse' »




Comments
comments powered by Disqus

MajorGeeks.Com » News » June 2012 » Wyndham Hotels fined over data breach

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition