Hospitality & Tourism — Cyber Threat Activity

Hospitality and tourism is attacked for payment data, guest records and the fact that it cannot close. Our log records more than 360 incidents across 58 countries, over 125 in the trailing 180 days, with 61 groups attributed at least one claim: Qilin (48), Akira (38), Play (29), LockBit (25) and RansomHub (24) lead. Hotels, casinos, restaurant groups and travel operators run high-turnover frontline workforces, franchised estates where security standards vary by owner, and property management, booking and point-of-sale systems that are internet-facing by necessity. An outage is immediately visible to customers, which is precisely why extortion works here: a chain that cannot check guests in negotiates faster than one that merely loses back-office access. The sector is also a favoured target for social-engineering crews who call help desks and talk their way past identity verification rather than exploiting software, a method CISA has documented in detail and which suits an industry where staff churn makes an unfamiliar caller unremarkable. There is a quieter espionage angle as well: state operators have targeted hotel reservation systems to establish where specific individuals were staying and to conduct reconnaissance ahead of official travel, which makes guest data a surveillance asset rather than a fraud commodity. Recorded geography is United States-led at 133 claims, then Spain, the United Kingdom, Canada, France and Australia, a spread that tracks tourism volume rather than any strategic selection. These figures are extortion-site claims rather than confirmed breaches, and card-fraud incidents handled privately through payment brands are largely absent from them.

All sectors

Recent incidents

Threat actors targeting Hospitality & Tourism

Where these victims are

Malware used against Hospitality & Tourism

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Coverage. 94.8% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions