April 21, 2025
The Hotel Hackers Are Hiding in the Remote Control Curtains
Back doors to your personal data can be found in everything from smart fish tanks to Wi-Fi pineapples.
Back doors to your personal data can be found in everything from smart fish tanks to Wi-Fi pineapples.

Three men dressed for business travel in jeans and dress shirts loaded backpacks into the trunk of a black coupe and wound their way through the center of a major European city. When they arrived at their hotel, they unloaded their luggage and waited giddily to pass through the revolving doors. They were checking into the hotel to hack it.

Hackers target financial institutions because that’s where the money is, and they target retail chains because that’s where people spend the money. Hotels might be a less obvious target, but they’re hacked almost as often because of the valuable data that passes through them, like credit cards and trade secrets. Thieves have targeted electronic door locks to burgle rooms and used malware attacks to log credit card swipes in real time. They’ve even used Wi-Fi to hijack hotels’ internal networks in search of corporate data. Just about all of the industry’s major players have reported breaches, including Hilton Worldwide Holdings, InterContinental Hotels Group, and Hyatt Hotels.

The group’s leader checked in at the front desk. One of his associates strolled along the length of the reception area, noting that the property used an outdated point-of-sale system, and another used a mobile app called Fing to scan for hidden networks. While they waited for the staff to finish preparing their room, the hackers took coffee on a terrace. They opened up the published code for the hotel website and exploited an outdated plug-in to compile a list of admin names.

Ultimately they were looking for a door. Sure, they could slip a thumb drive into the neglected register at the far end of the restaurant bar and log credit card numbers until somebody noticed the device. But they would rather find a way into the property management system, or PMS, which hotels use to take reservations, issue room keys, and store credit card data.

[…]