Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - These are not the droids you are looking for.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Halloween Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Smart Defrag
3. Macrium Reflect FREE Edition
4. Sergei Strelec's WinPE
5. MusicBee
6. K-Lite Mega Codec Pack
7. Visual C++ Redistributable Runtimes AIO Repack
8. Format Factory
9. FlyOobe / Flyby11
10. ImgBurn
More >>

top reads

Star 8 Windows Shortcuts That’ll Make You More Productive and Save You Time

Star Windows 10 Not Dead Yet - You Can Still Get Updates For Free

Star What is a '400 Bad Request - Request Header or Cookie Too Large' Error and How to Fix It

Star How to Fix Windows Install Error 0xC1900101

Star How to Force Enable Windows 10 Extended Security Updates If The Option Is Not Showing

Star Windows 11 25H2 is Out: What’s New and How to Get It Now.

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star Boost Your PC Speed with ReadyBoost: How a Thumb Drive Can Enhance Your System's Performance

Star 5 Hidden Windows Tools You’ve Had All Along But Never Use

Star Use the Windows 10 Media Creation Tool Before Support Ends For Windows 10 in 2025


MajorGeeks.Com » News » June 2012 » Wyndham Hotels fined over data breach

Wyndham Hotels fined over data breach


Contributed by: Email on 06/26/2012 02:00 PM [ comments Comments ]


The U.S. Federal Trade Commission has fined Wyndham Hotels for a string of data breaches that resulted in information on hundreds of thousands of customers being lost to cyber criminals.

An FTC complaint, filed on June 26, 2012, asks for "permanent injunctive relief" against Wyndham for failing to maintain what the FTC calls "reasonable security" necessary to keep intruders from compromising the network of the hotel chain. Wyndham's failure to protect its IT network laid the groundwork for a series of three data breaches in which cyber criminals based in Russia stole financial information later used to generate $10.6 million in fraudulent purchases. A Phoenix, Arizona, data center used by Wyndham was the source of the breach, the FTC said.

The complaint describes an epic failure on the part of Wyndham. It alleges that Wyndham Worldwide failed to adequately protect a property management system that was used to manage some 7,000 hotels under the Wyndham Hotels and Resorts under the Days Inn, Ramada and Super 8 brands. Among other things, the Wyndham is alleged to have used default administrative user names and passwords on servers that connected to the Hotels and Resorts network. Also, Wyndham Worldwide stored customer credit card data in plain text, and failed to adequately segregate the property management system from the company's corporate intranet and the public Internet.

The result was a string of security breaches between April 2008 and January 2010 and the theft of customer data.

Beginning in April, 2008, hackers were able to hop scotch from a single Wyndham Hotel's network to the entire Hotels and Resorts network through the company's central property management system. Using a brute force attack, the hackers compromised an administrative account on Hotels and Resorts network. Wyndham, the complaint alleges, failed to notice the intrusion attempt, despite the fact that the hackers guessing resulted in more than 200 administrative accounts getting locked out in the process. Among other things, the company lacked an adequate inventory of its IT assets and was thus failed to correlate the failed login attempts to just two computers in the company's Phoenix data center.

The first attack went undetected for four months, the FTC complaint alleges. In the end, the property management system servers of 41 Wyndham-branded hotels were involved in the breach and payment information on 500,000 accounts was compromised. Much of that information was exported to a server on a domain registered in Russia.





« Daily Reviews Summary 06/26/12 (32 Reviews) @ NT Compatible · Wyndham Hotels fined over data breach · Jealous husband ate wife's lip 'on impulse' »




Comments
comments powered by Disqus

MajorGeeks.Com » News » June 2012 » Wyndham Hotels fined over data breach

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition