---
title: Pandemics Create New Attack Opportunities in Travel and Hospitality
description: Modern tokenization, combined with intelligent data discovery, creates the ability for automated data protection built directly into business processes
image: https://insights.comforte.com/hubfs/Plane_v1.6.jpg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![Data breach during Pandemic - comforte AG](https://insights.comforte.com/hubfs/Plane_v1.6.jpg)](https://insights.comforte.com/pandemics-create-new-attack-opportunities-in-travel-and-hospitality)

[Mark Bower](https://insights.comforte.com/author/mark-bower) l Jul 21, 2020 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Pandemic](https://insights.comforte.com/tag/pandemic)

# Pandemics Create New Attack Opportunities in Travel and Hospitality

Hospitality and travel data breaches in a pandemic create new risks and threats to citizens on a global basis. Data breaches from airline, travel, and hospitality IT and cloud platforms present a potential worst case risk in the current climate. A common pattern in pandemic management today relates to travel companies using contact tracers to advise passengers on flights and in hotels about potential exposure risks to COVID-19. A colleague of mine was recently on an essential flight across the US with a single identified super-spreader. At least 50 people on the flight have been infected, as well as their families, so the risk is real and present.

While clearly necessary and essential, alerts from contact tracers no doubt create strong reactions and significant concern for those impacted. Hearts sink on bad news like this, and given the recent surges of the virus, concern is at all-time high. The resultant fear and concern in turn create an opportunity for phishers looking for higher click-to-breach rates from panic reactions. **Spear phishing** using groomed and personal travel records encourages emotional responses from vulnerable consumers. So, looking at the pattern of recent attacks, a good chance exists that attackers are revisiting prior database thefts to mount a new phase of virus-related spear phishing. This trend will lead to further data theft and compromise for both citizens and enterprises alike. A phish to a corporate employee operating outside regular controls can be a valuable attack vector for deeper secondary compromise, and an attack that’s highly personalized can lead to a more probable click-to-breach pattern. Similarly, knowing a travel pattern for an employee also creates enticing spear phishing opportunities because they reflect recent stays, create opportunity for fake past billing ‘surprises’, fake overpayments, fake demands for payment, and other email message tricks to get to the click.

## Dangerous trend?

Let’s ask the obvious question: is a serious trend emerging around this? Potentially. We recently saw the MGM breach of up to 142m records – an expansion from an earlier reported incident of cloud data compromise. Security researchers recently spotted a [cache of vast passenger records](https://cybleinc.com/2020/07/12/records-of-45-million-travelers-to-thailand-and-malaysia-leaked-on-darkweb/) circulating again for sale consisting of Thailand and Malaysia citizens. This could be a new breach, but more likely it’s an opportunistic attackers re-visiting the new value from last year’s Malindo/Lion Air breach, another cloud related incident but this time from insiders. This incident took place prior to COVID-19 but involved 46 million passengers’ records, including passport details. Another recent [property management corporate breach](https://cybernews.com/security/new-zealand-property-management-company-leaks-30000-passports-drivers-licenses/)has shown data from 30,000 citizens including passport photos and driver’s license details. Easyjet in Europe had a recent [breach of over 9 million identities](https://www.nytimes.com/2020/05/19/business/easyjet-hacked.html), Transavia suffered a[breach of 80,000 passengers](https://simpleflying.com/transavia-data-breach/,) and India’s Spicejet was also breached with[1.2 million records exposed](https://techcrunch.com/2020/01/30/spicejet-breach-millions-passengers/).

It’s always questionable as to why such high volume data sets are available to either insiders or attackers in the first place with seemingly few controls, but a major factor in the extent of these breaches is the potential availability of copies of data, shared data in cloud platforms, and redundant data from a past process (such as analysis or investigations that have not been expired or destroyed and are now within the realm of the “great unmanaged data” world). Let’s also not forget that Marriott and Choice Hotels have also sustained breaches – data that could possibly be re-purposed in the manner described by the criminally motivated – all pre-COVID-19 and adding to the increasingly large pot of data on traveler and guests globally.

## Cloud offers agility

Beyond the harsh economic conditions of the pandemic, a major challenge for enterprises, especially those in the hospitality industry, is first knowing what personal data exists and where it is within less controlled environments in particular. For example, with the shift to **cloud-based applications**, more and more organizations are also taking advantage of the agility that cloud services offer – yet many organizations still use production data to test in less protected cloud instances of IT where vulnerabilities are more common during development processes. Data thus often finds its way into many corners of the enterprise from production extracts for analysis, extracts for test, and extracts for innovation and insight. This represents a huge risk from insiders, and even greater risk of compromise from mistakes, attacks, or purposeful exploitation.

## Data-centric approach 

The number of breaches of S3 buckets or misconfigured cloud orchestration systems leading to leakage is quite staggering, even affecting well-prepared organizations like MGM. S3 storage is relatively simple yet mistakes happen. Even more complex cloud infrastructures, storage, and container application orchestration systems are now in accelerated adoption – cloud breaches are likely to rise in line with complexity. Yet there’s really no reason why such critical personal data can’t be protected everywhere, including the cloud, with [modern approaches like tokenization](https://www.comforte.com/fileadmin/Collateral/eBook_Data_Protection_Methods_Explained.pdf) to nullify the risky sensitive data from the hands of attackers especially in databases, data lakes, cloud storage, and cloud SaaS applications. Modern tokenization, combined with intelligent data discovery, creates the ability for automated data protection built directly into business processes, application development pipelines, and DevOps processes for both production and test as well as non-production scenarios – avoiding the need to store data such as in the breach involving 46 million records, which clearly lacked data-centric protection and which is now for sale on the dark-web. Given the ease of implementation, I can find no valid excuse not to take a modern approach deserving of customer’s expectations of contemporary privacy and security standards. Even in complex distributed booking systems, tokenized can be applied quickly. Anyone interested in seeing how this works should [contact us.](https://www.comforte.com/contact/)

Given recent incidents, though, recent hotel guests and current travelers should be vigilant and look out for (and even anticipate) suspicious emails purporting to be travel- and potentially pandemic-related. If this occurs, look carefully at the email’s origin and search for signs of phishing to avoid being a double victim of a breach, and then a successful phish.

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/pandemics-create-new-attack-opportunities-in-travel-and-hospitality&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/pandemics-create-new-attack-opportunities-in-travel-and-hospitality&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/pandemics-create-new-attack-opportunities-in-travel-and-hospitality&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/pandemics-create-new-attack-opportunities-in-travel-and-hospitality&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/pandemics-create-new-attack-opportunities-in-travel-and-hospitality&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Break the cycle of data breaches by rendering data useless (but only to attackers)

Tokenization replaces sensitive data elements with non-sensitive elements with no exploitable value.  In many cases, you can even perform analytics on tokenized data, eliminating the risk of exposing sensitive data during processing. Security travels with the data in house and in the cloud. Check out our solution brief to learn more:

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/e0644934-0050-47fc-9c48-1e4a598112be.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/e0644934-0050-47fc-9c48-1e4a598112be)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>