---
title: The Top 4 Reasons Why Hotels Keep Getting Hacked
description: There are a number of unique factors that make hotels particularly attractive targets for hackers. Let's take a look at the top four, and what can be done.
image: https://insights.comforte.com/hubfs/BP_data_privacy_1.jpg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![BP_data_privacy_1](https://insights.comforte.com/hubfs/BP_data_privacy_1.jpg)](https://insights.comforte.com/the-top-4-reasons-why-hotels-keep-getting-hacked)

[Warren Poschman](https://insights.comforte.com/author/warren-poschman) l Apr 4, 2019 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# The Top 4 Reasons Why Hotels Keep Getting Hacked

## Does your hotel need a wake-up call of its own?

In a trend that continues to escalate against so-called “softer” targets, the travel and entertainment industry has been bearing the brunt of many of the data breaches of late. There are some specific reasons why this has been happening to hotels in particular and I expect the trend to not abate any time soon. However, the industry does have options – if they choose to schedule a wake-up call and start taking action now.

Part of the problem that hotels have is clearly the large amount of data they collect and retain in their data warehouses. Like other softer targets, such as localities and state governments, they maintain a high volume of detailed information on clientele because they need it to do their job. But having lots of data isn’t  what makes hotels vulnerable in particular – it’s the challenges of the industry. There are four main reasons why hotels keep getting hacked:

- **Lots of mergers, acquisitions, and divestitures** – Consolidation is a huge risk because differing IT policies and procedures have to be merged and changed, and often with those changes come personnel changes. Keeping track of who did what and how is an easy way to expose vulnerabilities, not to mention vulnerabilities that may already have been exploited, as was the case with Starwood / Marriott.
- **Open systems with large amounts of franchisees** – The hotel industry is largely run on a franchise model with each hotel having some latitude on how they run their house with their own local partners while having access to the central systems. This makes the risk of introducing malware and other attacks so much higher than it does in the closed systems of banks and payments and, as retailers and restaurants have found, these threats are hard to contain, even with rigorous enforcement of front of house systems.
- **Inconsistent and aged investments** – Hotels are not IT powerhouses. Frankly, IT-wise many guests only care that their reservation and billing info is accurate and that they can get on the Wi-Fi. Hotels inconsistently invest in infrastructure when it isn’t visible to guests and doesn’t directly drive revenue. Likewise, the investments that are made are used as long as possible, while patching and updating can be spotty. It shouldn’t take a major breach to drive that investment!
- **Internal threats like no other** – No one likes to point fingers at employees but the realities are that hotels have been the scene of identity theft and credit card fraud since the beginning – think credit card skimming “swipe through” schemes. Background checks or not, front of house hotel employees have much easier access to customer data and there are lots of employees that require access, not to mention those staff have a high turnover rate.

These challenges are tough to manage and would-be attackers are all too keen to them. Without directly dealing with them, hotels are going to keep being ripe targets for attack.  However, there are things that can be done to change the trajectory – but it will take a loud wakeup call for many vendors, sadly.

## So what can hotels do about it?

Hotels have a lot of choices, including strengthening firewalls, intrusion detection, encrypting data, and limiting access to data through access controls. But, focusing on infrastructure, perimeter, and intrusion detection is a losing battle since these measures only protect you from the threats you know about and don’t offer any protection once compromised or circumvented. Furthermore, many hotel chains have heavily invested in passive, data-at-rest encryption protection for their storage, databases, and data warehouses – which unfortunately doesn’t address the current threat vectors and only provides a false sense of security.

The key is to think about what the attackers are after at the hotel chains – the data warehouse – and how that great resource can be used while preventing abuse. Adopting a data-centric security model allows for the data to be protected as it is acquired and traverses through the organization and, if an attacker gains access through the perimeter, then the risk that the actual personal data will be exposed is dramatically reduced. Data-centric protection with technologies like tokenization allows the organization to use the protected data for their operations, analytics and data sharing, meaning that any exfiltrated data would be useless tokens and considered out of scope of a data breach. Guest safety and privacy has to extend through the full environment, not just the front doors!

 

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/the-top-4-reasons-why-hotels-keep-getting-hacked&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/the-top-4-reasons-why-hotels-keep-getting-hacked&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/the-top-4-reasons-why-hotels-keep-getting-hacked&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/the-top-4-reasons-why-hotels-keep-getting-hacked&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/the-top-4-reasons-why-hotels-keep-getting-hacked&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Data privacy, please!

You've already got blackout curtains and Do Not Disturb signs to protect your guests' privacy. Now it's time to start protecting their data privacy. Read our solution brief to learn more about how tokenization and data-centric security can protect the personal data of your guests, no matter if you **move it** between systems, **use it** for processing, **leave it** stored in a database, or even **lose it** in a breach.

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/e0644934-0050-47fc-9c48-1e4a598112be.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/e0644934-0050-47fc-9c48-1e4a598112be)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>