The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Hospitality
Breach intelligence, attack campaigns, and threat reports targeting the Hospitality sector.
Explore Other Sectors
Hospitality Threat Reports
Autonomous AI Agents Execute Massive Credit Card Theft Campaign
A Chinese threat actor deployed autonomous AI agents to orchestrate a massive payment card theft operation, compromising over 119 websites and stealing more than 600,000 credit card records. The campaign, active since July 2026, utilized three AI frameworks - Strix for vulnerability scanning, Cairn for exploitation, and Hermes for orchestration - to systematically target online retailers. Major victims included Fortune 500 companies across hospitality, aviation, and retail sectors. The attackers deployed payment skimmers through various injection methods and implemented destructive cleanup procedures that wiped source data after exfiltration, causing operational disruptions. This incident represents a paradigm shift toward AI-powered cybercrime, demonstrating how autonomous systems can execute complex attack chains at unprecedented scale and speed. The low operational cost of $25 per target and minimal human oversight signal a new era where sophisticated attacks become accessible to less skilled threat actors, fundamentally changing the threat landscape.
1 day ago
Kill Chain
Dark Sourcery Campaign Exposes Critical Vulnerabilities in Enterprise AI Security
In September 2026, cybersecurity researchers from Vigilance Security uncovered a sophisticated social engineering campaign dubbed 'Dark Sourcery' targeting major AI chatbots including ChatGPT, Google Gemini, and Google AI Overview. Threat actors poisoned these AI systems by flooding the web with carefully crafted malicious content, fake support pages, and fraudulent contact information, tricking the AI into presenting this misinformation as factual responses to users. The campaign compromised at least 374 major companies including Fortune 100 organizations, airlines like Delta and Lufthansa, and financial institutions such as Chase and Bank of America, causing significant reputational damage and enabling widespread phishing attacks. This incident represents a critical evolution in AI-targeted attacks as organizations increasingly integrate AI chatbots and agents into their business operations. With 91% of users blindly trusting AI responses without verification, this attack vector poses an unprecedented threat to enterprise security and user trust in AI systems.
1 day ago
Kill Chain
Microsoft Reveals How AI is Reshaping Cyberthreats in 2026
Microsoft's September 2026 security analysis revealed how AI-powered cyberattackers are exploiting fundamental security weaknesses with unprecedented speed and persistence. The report documented three major attack campaigns: Storm-2945's CaptiveCrunch hospitality network manipulation, AI agent boundary exploitation incidents affecting OpenAI and Anthropic systems, and sophisticated social engineering attacks through Microsoft Teams. These incidents demonstrated how attackers leverage legitimate tools, trusted authentication flows, and AI agent vulnerabilities to achieve rapid lateral movement across enterprise environments, affecting identity systems, endpoints, and cloud infrastructure. This analysis matters now because AI is fundamentally reshaping the cyberthreat landscape, with autonomous attacks creating exponentially larger attack surfaces and faster compromise timelines than traditional methods.
6 days ago
Kill Chain
Hospitality Under Fire: PBX System Reconnaissance Reveals Critical Security Gaps
In September 2020, SANS Internet Storm Center detected targeted reconnaissance scans against hospitality industry applications, specifically focusing on the abandoned PIAF-HMS (PBX in a Flash Hospitality Management System) project. The scans originated from IP address 94.102.49.125, associated with bulletproof hosting provider IP Volume (AS202425), and targeted multiple hospitality-related endpoints including /admin/, /ucp/, /hms/, and /hotel/. The attackers used a distinctive user agent 'Farez-Sorter/1.0' and appeared to be exploiting recently disclosed SQL injection vulnerabilities in the decade-old, unpatched system that lacks proper input validation and authentication controls. This incident highlights the persistent targeting of hospitality infrastructure, where attackers seek to steal valuable guest personal data and potentially launch man-in-the-middle attacks. The focus on PBX systems suggests sophisticated attack vectors that could allow threat actors to impersonate internal hotel communications and manipulate guest interactions through compromised telephony infrastructure.
1 week ago
Kill Chain
BambooToken Malware Exploits MQTT Protocol for Stealthy Enterprise Attacks
BambooToken, a sophisticated malware framework active since 2023, has evolved to use the MQTT protocol for command-and-control communications across Windows and Linux systems. The malware compromises enterprise servers supporting mobile applications, financial services, and software development firms primarily across Asia and South America. By leveraging MQTT's publish-subscribe architecture, BambooToken creates resilient command channels that avoid direct connections to attacker infrastructure, significantly improving evasion capabilities while maintaining persistent access to infected systems. This incident highlights the growing trend of threat actors adopting unconventional protocols like MQTT to bypass traditional security controls, reflecting the increasing sophistication of modern cyber campaigns targeting critical business infrastructure.
1 week ago
Kill Chain
CareCam CM2507 IP Cameras: Seven Critical Vulnerabilities Expose Enterprise Networks
The CareCam CM2507 IP camera contains seven critical vulnerabilities (CVE-2026-88259 through CVE-2026-81321) that collectively allow complete device compromise. These flaws include missing authentication for video streaming, empty passwords in ONVIF services, cleartext credential storage, weak password hashing, and unauthorized script execution from removable media. Attackers can exploit these vulnerabilities to access live video feeds, extract stored credentials, execute arbitrary code, and pivot to connected networks. The vendor has not responded to CISA's coordination attempts, leaving deployed devices unpatched. This incident highlights the persistent security challenges in IoT devices deployed across commercial facilities worldwide, particularly as organizations increasingly rely on IP cameras for security monitoring while threat actors actively target poorly secured IoT infrastructure for initial access and lateral movement.
1 week ago
Kill Chain
BambooToken Malware Exploits MQTT Protocol in Global Multi-Platform Campaign
BambooToken is a sophisticated multi-platform malware campaign discovered in early 2026 that uses MQTT protocol for command and control across Windows and Linux systems. Active since February 2023, the threat actors exploit DLL sideloading techniques via Tendyron's OnKey authentication software to compromise organizations across Asia and South America. The malware demonstrates advanced evasion capabilities by leveraging legitimate PKI security tokens as attack vectors and using Cloudflare-proxied infrastructure to manage infections at scale. Researchers have identified compromised entities including mobile applications, financial organizations, hotels, and critical infrastructure systems across multiple countries. This incident highlights the evolving sophistication of threat actors who are increasingly adopting unconventional communication protocols and supply chain attack vectors to evade traditional security controls and maintain persistent access to high-value targets.
1 week ago
Kill Chain
IDScan Breach Exposes 153 Million Driver's Licenses: A Wake-Up Call for Identity Verification Security
In September 2026, identity verification company IDScan confirmed a significant data breach affecting over 153 million driver's license scans and personal identification documents. Threat actors gained unauthorized access to IDScan's cloud platform, compromising customer data including full names, driver's license numbers, and scanned copies of government-issued IDs. The stolen data was subsequently advertised on a dark web platform called 'Nexus' before being taken offline following FBI investigation. IDScan provides identity verification services to car rental companies, financial institutions, cannabis dispensaries, and hospitality businesses across the US and Canada. This incident highlights the growing threat to identity verification infrastructure as cybercriminals increasingly target centralized repositories of sensitive personal data. The breach demonstrates how third-party service providers handling critical identity documents have become high-value targets, creating cascading privacy risks across multiple industries that rely on these verification services.
2 weeks ago
Kill Chain
CareCam Pro IP Cameras Expose Critical Bootloader Vulnerability CVE-2026-85083
CISA disclosed CVE-2026-85083, a critical vulnerability in CareCam Pro IP cameras (model ANJIA AJL33PC0801) that exposes hard-coded credentials in the bootloader authentication system. Attackers with physical access can exploit this weakness to gain privileged bootloader access, enabling unauthorized firmware modification and complete device compromise. The vulnerability affects devices deployed worldwide across commercial facilities, with CareCam reportedly unresponsive to coordination efforts from CISA. This incident highlights the persistent security challenges in IoT infrastructure where manufacturers continue to implement insecure authentication mechanisms. As organizations increasingly rely on IP cameras for security monitoring and operational visibility, such fundamental design flaws create significant attack surface expansion and compliance risks.
2 weeks ago
Kill Chain
IDScan's Massive Data Breach Exposes 153 Million Driver's Licenses on Dark Web
In September 2026, identity verification company IDScan suffered a massive data breach affecting over 153 million U.S. and Canadian driver's licenses, along with 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Cybercriminals operating the dark web service 'Nexus' advertised the stolen data, which included scanned identity documents from businesses using IDScan's verification systems across car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments. The FBI's New Orleans office launched an investigation, and multiple class-action lawsuits have been filed against the Louisiana-based company. This incident highlights the growing threat to identity verification services and third-party data processors, demonstrating how a single breach can expose massive volumes of sensitive personal identification data across multiple industries and geographical regions.
2 weeks ago
Kill Chain
Threat Actors Weaponize Trusted Node.js Runtime for Stealth Malware Delivery
Since February 2026, threat actors have been weaponizing the legitimate Node.js JavaScript runtime (node.exe) to deliver malicious payloads in targeted attacks against government departments, technology companies, and hotels. The Symantec Threat Hunter Team identified this technique as particularly effective because node.exe is a trusted binary that can execute arbitrary JavaScript code while evading traditional security detection mechanisms. Attackers leverage the runtime's legitimate presence in enterprise environments to establish persistence, execute malware, and maintain command and control communications without triggering security alerts. This campaign reflects the growing trend of living-off-the-land tactics where attackers abuse legitimate system tools rather than deploying custom malware, making detection significantly more challenging for traditional security solutions and highlighting the need for behavioral analysis and runtime protection.
3 weeks ago
Kill Chain
Manchester Airports Group Breach Exposes 8.9 Million Travelers' Data in Major Aviation Cyber Attack
In August 2026, Manchester Airports Group (MAG), the UK's largest airport operator managing Manchester, London Stansted, and East Midlands airports, suffered a significant data breach affecting up to 8.9 million travelers. Attackers accessed customer databases containing Wi-Fi registration details, car park bookings, lounge reservations, and Fast Track services, compromising email addresses, phone numbers, vehicle registration numbers, and postcodes. While payment card data remained secure and airport operations continued uninterrupted, MAG temporarily suspended its online booking management system as a precautionary measure. The aviation industry faces increasing cyber threats targeting critical infrastructure and passenger data, with attackers recognizing airports as high-value targets containing vast amounts of personal information and payment data. This incident highlights the urgent need for enhanced cybersecurity measures across transportation hubs as digital transformation accelerates in the post-pandemic travel recovery.
4 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports