The leading company InterContinental Hotels Group PLC (also known as IHG Hotels & Resorts) says that its IT systems have been down since yesterday after the breach of its network.
See also: The US "took down" the criminal marketplace WT1SHOP

IHG is a British multinational company that currently operates 6.028 hotels in more than 100 countries and has more than 1.800 in the development stage.
Its brands include luxury, premium and basic hotel chains such as InterContinental, Regent, Six Senses, Crowne Plaza, Holiday Inn and many others.
See also: MooBot botnet targets unpatched D-Link routers
«InterContinental Hotels Group PLC (IHG) reports that parts of the Company's technology systems have experienced unauthorized activity», the company said on Tuesday.
“The booking channels and other IHG applications have been significantly disrupted since yesterday.”
The global hotel group has hired external experts to investigate the incident and is informing the relevant regulatory authorities.
Signs of a ransomware attack?
Although the company did not disclose details about the nature of the attack, it did say in its disclosure that it is working to restore the affected systems.
This suggests a possible ransomware attack where threat actors have deployed ransomware payloads and encrypted systems on IHG's network.
In most ransomware incidents, intruders will steal sensitive information from target networks before encryption.
This is later used in double extortion schemes , where victims are pressured to pay a ransom under the threat of leaking stolen data.
"IHG is working to fully restore all systems as soon as possible and to assess the nature, extent and impact of the incident," IHG added.
See also: Zyxel: New NAS firmware fixes critical vulnerability

“We will support hotel owners and operators as part of our response to the ongoing service disruption. IHG hotels are still able to operate and take direct bookings.”
Last month, the Lockbit ransomware gang claimed responsibility for the attack on the Holiday Inn Istanbul Kadıköy, one of the hotels managed by IHG.

Cybercrime intelligence firm Hudson Rock says IHG has at least 15 compromised employees and more than 4,000 compromised users, according to data linked to the ihg[.]com domain.
The giant hotel chain was the target of a security breach for three months in 2017 – between September 29 and December 29 – when more than 1,200 InterContinental- managed hotels in the United States were affected .
Information source: bleepingcomputer.com
