What Hotels Need to Consider When Handling Credit Card Data
„Your credit card has been blocked due to unusual transactions.“
This information was shared with me by my bank last summer while I was on my way to vacation. Through further information on the use of the credit card, I was able to trace the theft back to a booking at a hotel via the booking website booking.com. The reactions from booking.com and the hotel to my note about a potential security vulnerability were unfortunately very sobering and demonstrated a great lack of understanding. Booking.com even told me that everything must be secure on their end, as my credit card data was encrypted. This is true for the transmission of credit card data from my computer to the booking.com server. However, from there, credit card data is usually forwarded unencrypted via fax to the hotel, along with the rest of the booking information. It is likely that this fax fell into the wrong hands at the hotel. Thus, instead of a beautiful beach vacation, the hotel and booking.com are remembered in my mind by nerve-wracking phone calls to clarify a credit card data theft.
Hotels in the Crosshairs of Criminals
This story shows that hotels are in the crosshairs of criminals. They are after the vast amount of personal and financial data generated in the hotel industry. Reports of IT security incidents in hotels are increasing. Just recently, on June 27, 2016, the Hard Rock Hotel in Las Vegas had to inform its guests about a massive theft of credit card data. This shows that even large hotel chains do not assign the same high priority to modern IT risks as, for example, fire protection has enjoyed in the hotel industry for a long time.
Hotels Must Be PCI-DSS Compliant
In fact, since the end of 2013, all hotels that accept credit cards are subject to the regulations of the Payment Card Industry Data Security Standard (PCI DSS). This standard regulates the security precautions that credit card acceptance points of the major credit card companies, such as Visa and Master Card, must fulfill. In the event of non-compliance with the standards, penalty fees can be imposed and the acceptance of credit cards can be prohibited.
PCI-DSS Compliance of External Service Providers Must Be Verified
Many hotels use credit card terminals from a payment provider at the reception and have integrated a booking engine from an external provider. In these cases as well, they are fundamentally subject to the PCI-DSS regulations. The scope of the security measures that must be adhered to and demonstrated via a questionnaire (the Self Assesment Questionare SAQ) differs however according to the type of credit card data processing. Depending on whether credit card data only exists on paper or is also stored digitally, differently strict requirements apply. Typically, hotels must answer the SAQ-B with 38 questions or the SAQ-B-IP with 62 questions. Details on the hotel-typical requirements for these questionnaires are contained in the PCI guide of the hotel association IHA. However, as soon as credit card data is stored electronically (for example in emails or as scans), hotels must fulfill the requirements of the most extensive questionnaire SAQ-D with 241 questions. Additionally, the hotelier is obliged to have the PCI-DSS compliance of their credit card service providers proven. This affects, for example, channel managers, voucher shops, and online booking engines.
Typical Dangers When Handling Credit Card Data
Finally, we would like to warn against some frequently encountered errors when handling credit card data in hotels. These bring, on one hand, the risk of credit card data theft and, on the other hand, violate PCI regulations.
Digital Storage of Credit Card Data
Just because a hotel does not request credit card data from guests via email does not mean that guests do not send it anyway. If these emails are not immediately and comprehensively deleted, the hotel would fall into the highest risk class SAQ-D in the PCI-DSS requirements. But the handling of fax messages must not be forgotten either. These now also arrive via e-fax electronically. If these, as in the story of the booking.com booking confirmation described at the beginning, contain credit card data, the damage from the actual credit card theft is quickly accompanied by an investigation into a possible violation of PCI rules.
Unsecure Booking Paths
A second vulnerability we frequently observe occurs in the realization of booking paths on hotel websites via the Internet Booking Engine (IBE) of an external provider. The booking engine is usually integrated using a so-called https-iframe. This ensures that the credit card transaction is fundamentally encrypted via TLS on the server of the IBE provider. However, a security vulnerability arises if the hotel website in which the IBE is integrated is delivered unencrypted via http. Through this, criminals can manipulate the content of the website with a so-called Man-in-the-Middle attack and thus replace the actually secure iframe with a copy that reads the credit card data of the hotel guests. This becomes particularly delicate in the case of a hotel where the Man-in-the-Middle attack on the hotel website is made possible by an unsecure hotel WLAN from within the house. But that is a story for another blog post.
Contact us if you have doubts about which SAQ category your hotel falls into for proof of PCI-DSS compliance or how you can implement the required security measures. The consultants at aramido have the necessary IT security know-how as well as operational experience in the hotel industry and can thus advise you optimally on all issues. Arrange your free initial consultation now!
On 01.07.2016 in the category Data Security published.

