Best Western Loses Details On 8 Million Customers
Albanach writes "Scotland's Sunday Herald newspaper has an exclusive report that the Best Western hotel chain has lost the personal details of each and every guest who has stayed at any of its 1300 hotels in the past 12 months. This amounts to details on 8 million customers and includes information such as name, address, credit card details and employment details. The data even includes future booking details, causing speculation that homes could be targeted for burglary when it's anticipated they will be unoccupied. A Best Western spokesperson is quoted as saying 'Best Western took immediate action to disable the compromised log-in account in question. We are currently in the process of working with our credit card partners to ensure that all relevant procedural standards are met, and that the interests of our guests are protected.'"
The Sunday Herald article is amazingly unclear about the scope of this breach. Which hotels are affected? The article says all "continental hotels". Does that, from a British Newspaper, mean european continental hotels only?
I stayed at Best Western in the US late last year. Luckily, I have since then changed to a different credit card than the one I used at the time.
The last time when a company I did business with lost my credit card details, I decided I wouldn't do anything about it until I really saw an unauthorized withdrawal from my account. Because in the past, when there was an unauthorized withdrawal (only happened to me once), a single phone call to the credit card company had been enough to get my money back (some 300 Euro). They said they would start to investigate it, but because it could take a long time, "here's your money back as a first measure."
With the recently stolen card info, I got a notice from my bank a few months later that they had to disable my card because there was an attempt to commit fraud with it. I got a new card with no further action required on my part.
Either way, this could turn out to be a big hassle for Best Western. If only they could let me know if my personal data was affected.
The summary is misleading:
The details wern't "Lost", the server was comprimised and they were stolen.
This doesn't affect all Best Western hotels, just some European ones.
The details stolen are from 2007-2008 (up to 20 months)
'Best Western took immediate action to disable the compromised log-in account in question...
WHAT? In that case, they haven't lost the data due to carelessness (which I can just about forgive)- they've failed to secure their systems, which is criminally negligent.
Those using pirated Tinysoft signatures(TM) are a real threat to society and should all be thrown in jail.
From here :
Unlike other chains, which are often a mix of company-owned and franchised units, each Best Western hotel is an independently owned and operated franchise. Best Western does not offer franchises in the traditional sense (where both franchisee and franchisor are operating for-profit), however. Rather, Best Western operates as a nonprofit membership association, with each franchisee acting and voting as a member of the association.
ich bin der musikant
mit taschenrechner in der hand
kraftwerk
We're getting "anti-terror" laws that cut away our civil liberties piece by piece, despite little to no terrorist activity anywhere. Yet we have "data loss" on an almost weekly base and nothing happens. Could anyone tell me why those companies are still in business? When did criminal neglect become less than a misdemeanor? Because, well, did you see anything happening out of it? I didn't.
These companies cause problems to their customers by their careless handling of personal and financial data. At the very least, they subject their customers to the threat that their credit card data is in the hands of a criminal, ready to use it whenever they please. When are we going to see some laws that mean consequences if you can't handle your customers' data?
Every company is very keen to collect everything about you, from your favorite dish to your shoe size, but they can't be bothered with the task to keep this information secure? If you can't keep info secure, don't collect it, dammit!
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
The issue is not so much that the data were stolen, though obviously that is bad; but that the hotel made it worse by keeping data on hand that weren't necessary. "Employment details"? WTF? I recognize that certain data are unavoidable in such a system; but I would like to see substantially greater penalties for those who compromise customer data that they don't even have a good reason for keeping.
Incidentally, when did we start using the term "lose" as a polite synonym for "fuck up in fine style"?
- The article states thats the passwords were leaked via a Microsoft desktop OS compromised by a password sniffing Trojan spread via a virus.
- Microsoft's OS and applications are disproportional at a far greater risk of being compromised than any other platform. That is a fact!
- Class action lawsuits are a valid method for the public to change the behavior of both large business and governmental agencies. For example, the EFF have been involved with many Class action lawsuits, to change the behavior of both business and governmental agencies.
Microsoft has been hinting that organizations deploying Linux are at risk from Microsoft's so called patents, however those same Microsoft customers face a much greater risk and loss from compromised Microsoft desktop systems.
And You Sir, are just another gutless Nym-shifing Microsoft Astroturd who is not even worth rating.
Most of the time, when I read a story along these lines (lost data, stolen data, client personal details incl. credit info), I have to ask myself "do they really need to archive all this data on their customers?"