Beware! Your hotel confirmation e-mails are vulnerable to misuse

Image
ANI Internet
Last Updated : Apr 10 2019 | 11:50 PM IST

Hotels across the globe send you e-mails upon booking confirmation. However, your next stay with them is not safe from the prying eyes of third-parties.

Security company Symantec found flaws in the websites of hundreds of hotel, which were leaking sensitive information including names, phone numbers, passport numbers, and addresses in confirmation e-mails, Cnet reports.

Hotels are the most vulnerable to hack attacks as they have a trove of information through guest check-ins. The researchers found two-thirds of over 1,500 hotel websites in 54 countries with issues in their websites.

One of the issues stems from the URL, which is sent to the guests in emails. These URLs also contain the booking number.

The vulnerable websites have advertisers and third-party analytics tools embedded on the pages who also get the URL.

All that a potential attacker needs to do is enter the reservation number and gather all the personal information tied to it.

The researchers recommend hotels to stop information in the URL and start implementing authentication measures on confirmation pages.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Apr 10 2019 | 11:30 PM IST

Next Story