HomeSecurityHotels.com and Booking.com customer data exposed publicly

Hotels.com and Booking.com customer data exposed publicly

The personal data of millions of customers has been exposed online and can be seen and used by anyone, due to a leak at Prestige Software. The company provides the largest online hotel services to Hotels.com, Booking.com and Expedia, which store data in an open cloud.

Booking.com

As recently discovered, the Madrid and Barcelona-based technology and computer company did not provide adequate levels of security for its online databases that store highly sensitive user information. The company's sites are a Amazon Web Services S3used in the hotel industry.

Security experts had warned that booking services were vulnerable to attacks and data breaches, and now it seems their predictions have come true.

The compromised database contains information such as full names, addresses, credit card information, national ID numbers and more, belonging to customers of the world's most popular and widely used booking services.

According to Website Planet, its security team recently discovered vulnerabilities and security risks in Prestige Software's online cloud system, which contains over 10 million user files.

Hotels.com and Booking.com customer data exposed publicly

A total of 24.4 gigabytes of user data are exposed to public view on the internet and anyone could use it for malicious purposes.

Prestige Software’s “ Cloud Hospitality ” is a channel management platform that automates the process for online booking sites like Booking.com and Hotels.com. The site discovered that its open database information had been exposed since 2013.

The exact number of users affected by the breach is not yet known, but it is certainly very large. Researchers have also not discovered any attacks related to the data leaked by Prestige Software.

According to Engadget, once a user enters all of their personal information into the booking platform, it will be automatically uploaded to the Cloud Hospitality subscription in an Amazon Web Services S3 bucket. Amazon Web Services is considered “misconfigured,” according to Website Planet, and is open to mass breaches. In addition to stealing personal information and credit card numbers, hackers can also steal a reservation to use for themselves.

Source: TechTimes

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS