InterContinental Hotels Group PLC has stated that its IT systems have been severely disrupted as a result of a network breach.
IHG is a British multinational hospitality company that currently operates 6,028 hotels in more than 100 countries. It currently is planning to open more than 1,800 over the coming years.
The company operates many well-known hotel chains, including InterContinental, Regent, Crowne Plaza, Holiday Inn, and many more.
IHG’s statement regarding their recent cyber attack was made to the London Stock Exchange and can be read in full here.
“InterContinental Hotels Group PLC reports that parts of the Company’s technology systems have been subject to unauthorised activity. IHG’s booking channels and other applications have been significantly disrupted since yesterday, and this is ongoing.”
“IHG has implemented its response plans, is notifying relevant regulatory authorities and is working closely with its technology suppliers. External specialists have also been engaged to investigate the incident.”
The global hotel group has also employed the services of cyber-security experts to investigate the incident and is notifying the relevant regulatory authorities.
Ransomware?
Hotels chains have become popular targets for cyber attacks, as they contain millions of instances of personal data, but are easier to breach than other organisations. Itay Click, CEO of Israeli cyber-security company Votiro, stated, “Hotels don’t have massive data centres like banks which create very secure systems to protect themselves.”
While the IHG group has not yet revealed any details regarding the cyber attack, it did mention in its statement that they are working on restoring impacted systems.
This suggests that a ransomware attack may have occurred, with the impacted systems suffering from threat actors deploying ransomware payloads and seeking to encrypt IHG’s networks.
In most ransomware incidents, the threat actors will also steal sensitive information from their victim’s network before encryption.
Holding sensitive information can then be used in double extortion schemes, where the target will then be pressured into paying a ransom under the threat of leaking the data or selling it to other threat actors.
It is also possible that IHG is not certain of the nature of the attack that they suffered, as the group added in the statement that “IHG is working to fully restore all systems as soon as possible and to assess the nature, extent and impact of the incident“.
As yet, no stolen IHG data has surfaced on any cybercrime forums. This indicates that while there is still the possibility of the disruption being caused by a ransomware attack, the threat actors do not appear to be using double extortion tactics.
Chris Vaughan, the AVP of Technical Account Management for EMEA has stated that this attack is “just the latest in a wave of attacks targeting the hotel sector“.
History of attacks
This is not the first attack suffered by the Hotel Group, with 1,200 franchised hotels in the US being hit by a three-month cyber attack in 2017, This attack sought to steal customer payment card data.
The malware in this instance searched for track data such as customers’ names, card numbers, expiration dates, and internal verification codes. The breach lasted from the 29th of September to the 29th of December, and the hotel declined to state at the time what losses were incurred or what financial impact the hack might have in the future.
One of the group’s hotels was hit as recently as last month when the Lockbit ransomware gang claimed an attack on Holiday Inn Istanbul Kadikoy.
Current Impact
The hotel group’s APIs (Application Programming Interfaces) are also down and showing 502 and 503 HTTP errors. Customers will be unable to log in for the time being, with their app displaying “Something went wrong. The credentials you entered are invalid. Please reset your password or contact Customer Care.”
Cyber security consultants brought in by IHG have identified at least 15 compromised employee accounts, and over 4,000 compromised user accounts.
IHG Group has denied commenting any further on the incident beyond its existing statement.







