Restaurants, bars, and other hospitality businesses often consider themselves immune against cyber attacks, especially when compared to organisations that are regularly targeted such as law firms and manufacturing companies.
However this could soon change as booking and payment systems are being increasingly targeted by cyber criminals.
SevenRooms – International CRM Platform

CRM platform “Seven Rooms”, recently suffered a serious data breach, one they only acknowledged after their data was found being sold on the dark web.

Seven Rooms is a restaurant customer management platform used by international restaurant chains and hospitality service providers. Notable clients include MGM Resorts, Mandarin Oriental, and Black Sheep Restaurants.

The Data Breach

On the 15th of December, a cyber criminal posted data samples from the breach on the Breached hacking forum, claiming to have stolen a 427 GB backup database with thousands of files containing the personal information of thousands of SevenRooms customers.

The samples were provided to add validity to the stolen database, with the cyber criminal hoping to sell the data through the forum.

The samples included folders named after clients of Seven Rooms, API keys, promotional codes, payment reports, reservation lists, and more:

The Cyber Criminal’s post selling data on the Breached forum

Cyber Security news outlet BleepingComputer contacted SevenRooms directly about the supposed breach, as they had not yet released any statement suggesting a data leak had occurred.

Official Statement

After this inquiry, SevenRooms did confirm that the data being sold was theirs, and it had been caused by unauthorised access into the systems of one of their vendors.

Here’s their complete statement:

SevenRooms recently learned that a file transfer interface of a third-party vendor was accessed without authorisation

This may have affected certain documents transferred to or by SevenRooms, including the exchange of API credentials (now expired), and some guest data, which may include names, email addresses and phone numbers

Fortunately for the CRM provider, their clients’ customers’ credit card information, bank account data, social security numbers, or other highly sensitive information was not stored on any of the servers that were compromised.

However the guests who had their emails and phone numbers leaked will be subjected to phishing and vishing attacks for the foreseeable future.

This data breach is notable, as SevenRooms confirmed that their systems have not been breached, but rather an organisation in their supply chain has flawed cyber security in place. SevenRooms also went on to confirm that their systems remain secure against unauthorised external access:

We immediately disabled access to the interface, launched an internal investigation, and we currently have no evidence that any of SevenRoom’s proprietary databases were affected“.

We have retained independent cybersecurity experts to assist with this investigation and will provide additional updates as appropriate“.

While it is currently unclear which restaurants and customers under SevenRooms’ care were affected by this breach, we will likely see further data breach notifications released by restaurants whose customers’ data was compromised by this breach.

TecSec Services Ltd is an IT Support and Risk Management provider.
We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body.
We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.
We are currently offering a free service that will help to identify if your organisation is at risk of being exploited by cybercriminals.
Our Free Cyber Security Training helps protect your staff against phishing attacks, by providing the current best methods of identifying phishing emails: