iTnews

Sabre investigating hack of user payments

By Staff Writers on May 3, 2017 10:55AM
Sabre investigating hack of user payments

Tech giant calls in Mandiant.

Technology systems provider Sabre has revealed an unknown attacker infiltrated its widely-used reservations system and accessed sensitive user payment information.

Sabre is a multinational technology company that provides solutions to the travel and tourism industry. Its customer list in Australia includes Virgin Airlines, and globally Hertz, Etihad, and Singapore Airlines, among others.

In a quarterly filing with the US SEC, first spotted by Brian Krebs, Sabre revealed an "instance of unauthorised access to payment information" contained within a subset of hotel reservations processed through its SynXis Central Reservations platform.

It claims 32,000 hotels across the globe use the hosted inventory management platform.

The technology company said it had asked FireEye's forensics unit Mandiant - which helped clean up the infamous Sony hack - to help with the investigation, and law enforcement has been notified.

It provided no other details of the breach.

Sabre told customers it had "shut off" the unauthorised access and there was no evidence of continued activity.

"There is no reason to believe that any other Sabre systems beyond SynXis Central Reservations have been affected," it said in a statement.

"Our Sabre hospitality solutions customers are being notified of the investigation with a commitment to keep them informed. 

"Consistent with our steadfast commitment to providing world-class security for our solutions and support for our customers, we have dedicated internal staff and independent cyber experts to complete this investigation as quickly as possible."

The disclosure follows the revelation of a similar breach at the Intercontinental Hotel Group, which last month said at least 1200 of its properties - which include brands like Holiday Inn - had been affected by malware installed at PoS machines by attackers to steal card credentials.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
breach leisuireit recreation sabre security travel

Partner Content

One way SD-WAN can save business leaders' time
Partner Content One way SD-WAN can save business leaders' time
What is zero trust cybersecurity?
Partner Content What is zero trust cybersecurity?
Improving returns from SD-WAN spending
Partner Content Improving returns from SD-WAN spending
Putting cyber security basics in place
Partner Content Putting cyber security basics in place

Sponsored Whitepapers

Encryption: Protect your most critical data
Encryption: Protect your most critical data
Overcoming data security challenges in a hybrid, multicloud world
Overcoming data security challenges in a hybrid, multicloud world
Move beyond passwords
Move beyond passwords
The top 5 tech trends to deliver business outcomes
The top 5 tech trends to deliver business outcomes
10 reasons why businesses need to invest in cloud security training
10 reasons why businesses need to invest in cloud security training

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
By Staff Writers
May 3 2017
10:55AM
0 Comments

Related Articles

  • Congress has new appetite for breach law following SolarWinds hack
  • Home Affairs ordered to compensate asylum seekers over 2014 data breach
  • Ubiquiti says cloud-hosted IT systems 'accessed' by unauthorised party
  • US Justice Department says its emails were breached by SolarWinds hackers
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

TPG Telecom to start enticing NBN customers to move

TPG Telecom to start enticing NBN customers to move

Infosys scores another $40m for Centrelink payments engine build

Infosys scores another $40m for Centrelink payments engine build

Telstra InfraCo opens up telco's own fibre network

Telstra InfraCo opens up telco's own fibre network

Transport for NSW data stolen in Accellion breach

Transport for NSW data stolen in Accellion breach

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.