Credit Card Breach at Hilton Hotels, Trump Also Targeted

Hilton said it is investigating the security breach with the help of third-party forensics experts, law enforcement, and payment card companies (Photo: Damien Meyer/AFP)

U.S. hotel chain Hilton revealed that hackers infected some of its point-of-sale computer systems with malware crafted to steal credit card information.

Hilton would not disclose whether data was taken, but advised anyone who used payment cards at Hilton Worldwide hotels between November 18 and December 5 of last year or April 21 and July 27 of this year to watch for irregular activity on credit or debit card accounts.

Malicious code that infected registers at hotels had the potential to take cardholders’ names along with card numbers, security codes and expiration dates, Hilton said in an online post.

Hilton said that it is investigating the breach with the help of third-party forensics experts, law enforcement and payment card companies.

The announcement came just four days after Starwood Hotels, which operates the Sheraton and Westin chains, said that hackers had infected payment systems in some of its establishments, potentially leaking customer credit card data.

Related: WATCH: The Online Hotel Booking Scam That’s Costing You Money


A view of the W New York - Times Square, which is part of Starwood Hotels. (Photo: NCinDC/Flickr)

The hack occurred at a “limited number” of its hotels in North America, according to Starwood, whose other well-known chains include St Regis and W Hotels.

Starwood said that an investigation by forensic experts concluded that malware was detected in some restaurants, gift shops and other points of sale systems at hotels.

“The malware was designed to collect certain payment card information, including cardholder name, payment card number, security code and expiration date,” the group said in a statement.

The cyber attacks on Hilton and Starwood sounded similar to one disclosed last month by Trump Hotel Collection.

Related: The Experts Give Credit: Best Rewards Cards for Travel

Trump Hotel Las Vegas. (Photo: Damien/Flickr)

“We believe that there may have been unauthorized malware access to some of the computers that host our front desk terminals and payment card terminals in our restaurants, gift shops and other point-of-sale purchase locations at some hotels,” Trump Hotel Collection said at a website devoted to details of the incident.

The access may have taken place between May 19 of last year and June 2 of this year, according to Trump hotels.

Locations affected were listed as Trump SoHo New York, Trump National Doral, Trump International New York, Trump International Chicago, Trump International Waikiki, Trump International Hotel & Tower Las Vegas, and Trump International Toronto.

An independent forensic investigation did not turn up evidence that customer information was removed, but not was provide by Trump hotels in “an abundance of caution,” according to the website.

Related: Use Your TV as a Phone Charger And More Helpful Hotel Tips

Data targeted by the malware appeared to include account numbers, card expiration dates, and security codes.

Cyber threats blogger Brian Krebs at KrebsonSecurity.com described the infiltration of Trump payment systems as “just the latest in a long string of credit card breaches involving hotel brands, restaurants and retail establishments.”

Krebs placed fault on slow adoption in the US of encrypted chip technology on payment cards that provide more protection for data than does magnetic strips.

WATCH: 5 Ways to Avoid Common Hotel Scams


Let Yahoo Travel inspire you every day. Hang out with us on Facebook, Twitter, Instagram, and Pinterest. Check out our original adventure travel series A Broad Abroad.