HEI Hotels announces breach of PoS systems

Aug 15, 2016 13:30 GMT  ·  By

HEI Hotels & Resorts informed customers over the weekend about a security breach of its payment system that affected 20 of its properties across the US.

The company says it received warning of a possible breach from its payment card processor last year. In a subsequent investigation, the company discovered security breaches dating back to March 2015 but later found that the vast majority of affected hotels were compromised after December 2015.

The company said that customers who made card purchases via point-of-sale terminals at food and beverage outlets at HEI properties might be affected.

PoS malware infected HEI Hotels payment systems

HEI says the malware had the ability to collect credit card data in real time, as the PoS system was processing the information. Exposed data may include details such as name, payment card account number, card expiration date, and verification code.

HEI, which manages more than 50 properties across the US, revealed a list of affected hotels in a statement on its site. The list includes properties in Chicago, Tampa Bay, San Francisco, Miami, Nashville, Philadelphia, Washington, Minneapolis, and more.

The company explains it contracted a security vendor to help investigate and clean out its systems. Cleanup operations took place over the spring.

"We are treating this matter as a top priority, and took steps to address and contain this incident promptly after it was discovered, including engaging outside data forensic experts to assist us in investigating and remediating the situation and promptly transitioning payment card processing to a stand-alone system that is completely separated from the rest of our network," HEI said in a statement.

"In addition, we have disabled the malware and are in the process of reconfiguring various components of our network and payment systems to enhance the security of these systems."

Below is a list of affected properties, their addresses, and the dates when the PoS systems were compromised. HEI might update this list at a later time, so you had better bookmark this URL for future references.

List of affected properties at August 15, 2016
List of affected properties at August 15, 2016

Photo Gallery (2 Images)

HEI Hotels suffers PoS system breach
List of affected properties at August 15, 2016
Open gallery