IHG ‘Unauthorized Access’, Systems Down

IHG has announced that parts of the company’s’ technology systems have been subject to ‘unauthorised activity‘. It appears this activity has been occurring since Sunday when the systems went down. Originally IHG was saying that this was due to scheduled maintenance but that is no longer the case with the following statement being provided:

InterContinental Hotels Group PLC (IHG or the Company) reports that parts of the Company’s technology systems have been subject to unauthorised activity. IHG’s booking channels and other applications have been significantly disrupted since yesterday, and this is ongoing.

IHG has implemented its response plans, is notifying relevant regulatory authorities and is working closely with its technology suppliers. External specialists have also been engaged to investigate the incident.

IHG is working to fully restore all systems as soon as possible and to assess the nature, extent and impact of the incident. We will be supporting hotel owners and operators as part of our response to the ongoing service disruption. IHG’s hotels are still able to operate and to take reservations directly.

A further update will be provided as and when appropriate.

It’s unclear what personal information or other data has been accessed at this stage. 1,175 IHG properties suffered payment terminal data breach in 2017 and in the end settled a class action lawsuit for $1.55 million. I’ve long stated that until the penalties increase for data breaches they will continue to occur at alarming rates.

Subscribe
Notify of
guest

18 Comments
newest
oldest most voted

Andy
Andy (@guest_1447469)
September 18, 2022 03:29

Apparently, the password to IHG’s database was Qwerty1234.

Not joking.

https://www.bbc.com/news/technology-62937678.amp

Lou
Lou (@guest_1442314)
September 10, 2022 00:59

I got a fraud email today using my first and last name in the subject line. It purports to be a receipt for something expensive, and has a number for me to call if any questions. The 0 and 1 in the number are “O” and “I”.

The fraud email was sent to the email account that I only use for IHG.

Has IHG confirmed they were hacked? Seems clear to me.

Michael Meyer
Michael Meyer (@guest_1439805)
September 7, 2022 08:06

Time for IHG to start implementing and frequently verifying GRC (governance, risk management, and compliance). PCI compliance, NIST framework, and CIS benchmarks. At minimum have account IT best practices such as ZTA (zero trust architecture), IAM (Identity Access Management), AAA (authentication, authorization, accounting), MFA (multiple factor authorization), and XDR. They should investigate their CI/CD pipeline and DevSecOps framework as well. Basic security practices in any sustainable business. Common sense is not that common.

TB
TB (@guest_1440327)
September 7, 2022 19:06

Lol its funny you wasted your time blabbering out all these buzzwords knowing IHG is probably never going to read this. I wouldn’t trust you implementing/validating all this for me.

Harcourt Fenton Mudd
Harcourt Fenton Mudd (@guest_1439514)
September 6, 2022 20:18

Aw, Snap!

JJWIN
JJWIN (@guest_1439485)
September 6, 2022 19:39

Be more incompetent ihg, you can’t

Andy
Andy (@guest_1439462)
September 6, 2022 19:23

Unauthorized access? What does that mean? Did someone book an overwater villa at the Intercontinental Bora Bora Thalasso on points?

LakeMich87
LakeMich87 (@guest_1439460)
September 6, 2022 19:20

This is exciting. I’ll take a class-action settlement check for $5, please.

LakeMich87
LakeMich87 (@guest_1439533)
September 6, 2022 20:51

fuck you you fucking piece of shit!

Epstein D.K. Himself
Epstein D.K. Himself (@guest_1439580)
September 6, 2022 21:53

What?

Billy Bob
Billy Bob (@guest_1439634)
September 6, 2022 23:30

Jekyll and Hyde

Epstein D.K. Himself
Epstein D.K. Himself (@guest_1439654)
September 7, 2022 00:30

That famously happened to me once.

TB
TB (@guest_1439385)
September 6, 2022 18:06

Sounds like a ransomware attack, IHG is scrambling to buy the BTC

qmc
qmc (@guest_1439365)
September 6, 2022 17:49

They should forcibly reset every customer’s passwords, and that’ll get rid of the last of the people who STILL haven’t updated from their 4-digit PIN, but feel like “sharing” with the rest of us about how bad they think it is.

Creditian
Creditian (@guest_1439372)
September 6, 2022 17:56

Why not just require for 10 passwords and each of them requires 10 upper cases and 10 lower cases along with 10 different symbols if you have problem with 4 digits PIN?

Creditian
Creditian (@guest_1439377)
September 6, 2022 18:00

Database breach has nothing to do with 4 digits PIN, idiot

qmc
qmc (@guest_1443034)
September 11, 2022 12:55

Read it again. I said they should take this opportunity (the breach) to reset every customer’s PINs, (idiot)

P
P (@guest_1439362)
September 6, 2022 17:45

So, this is like their 5-year plan, right?

2017, 2022, and now we have 2027 to look forward to.