IHG Data Breach Far Bigger Than Initially Reported

Image: PHOTO: Credit cards. (photo via Flickr/Sean MacEntee)
Image: PHOTO: Credit cards. (photo via Flickr/Sean MacEntee)
Patrick Clarke
by Patrick Clarke
Last updated: 11:20 AM ET, Wed April 19, 2017

In what has become an all-too-common occurrence for hotel guests, another major hotel chain has confirmed a payment card data breach affecting hotels across the U.S.

This past February the InterContinental Hotels Group (IHG), which owns popular brands including Holiday Inn and Crowne Plaza, announced it had launched an investigation into a series of unauthorized charges on cards that were used at a dozen properties between August 2016 and December 2016.

On Friday, IHG confirmed the malware was more widespread, affecting hundreds of properties.

The U.K.-based company said its investigation turned up signs of malware designed to access payment card data from cards used at the front desk of certain locations between September 29, 2016, and December 29, 2016.

The malware sought out track data from debit and credit cards' magnetic stripes. That data can include things like cardholder name, card number, expiration date and internal verification code.

According to KrebsonSecurity, cyber thieves typically target point-of-sale devices at hotel restaurants and bars, installing the malware via hacked administration tools. The thieves can then collect the data from each card that is swiped and have it encoded onto any card with a magnetic stripe.

IHG didn't say how many properties were affected, but guests can search by state and city to find out if their hotel was impacted and, if so, for what duration of time.

[READMORE] READ MORE: IHG Reports Payment Card Breach at 12 Properties [/READMORE]

The good news for guests is that hotels have begun adopting a solution to combat cyber thieves. IHG has been implementing Secure Payment Solution (SPS) to protect customers' payment card information moving forward.

IHG said that hotels where SPS was present prior to September 29, 2016, were unaffected. Many more properties implemented SPS after that date, according to IHG, thereby eliminating the malware threat.

IHG is just one of many hotel giants that have been victimized by malware in recent years. The list includes companies like Hilton, Trump Hotels, Starwood Hotels & Resorts, Hyatt Hotels and Kimpton.

It's always smart to review your payment card statements and monitor them for potential fraud. So long as any unauthorized charges are reported in a timely manner, cardholders aren't responsible for the charges.


For the latest travel news, updates and deals, subscribe to the daily TravelPulse newsletter.

Topics From This Article to Explore

More From TravelPulse

Related Videos

Patrick Clarke

Patrick Clarke

Senior Editor

A Maryland native and wanderer who has lived across the U.S. from North Carolina to SoCal, Patrick Clarke graduated from Towson University with a B.S. in journalism. He previously worked for Bleacher

Grow Your Travel Business With Certified Courses

Travel Agent Academy
Travel Agent Academy
Majestic Resorts Specialist ProgramDiscover all-inclusive luxury at Majestic Resorts in paradise.
Travel Agent Academy
Travel Agent Academy
Allianz Specialist ProgramProtect every journey with Allianz Partners Travel Insurance.
Travel Agent Academy
Travel Agent Academy
Los Cabos Specialist ProgramSell the magic of Los Cabos: luxury, adventure, and endless sunshine.
Travel Agent Academy
Travel Agent Academy
Majestic Resorts Specialist ProgramDiscover all-inclusive luxury at Majestic Resorts in paradise.
Travel Agent Academy
Travel Agent Academy
Allianz Specialist ProgramProtect every journey with Allianz Partners Travel Insurance.
Travel Agent Academy
Travel Agent Academy
Los Cabos Specialist ProgramSell the magic of Los Cabos: luxury, adventure, and endless sunshine.

Don't Miss These Travel Agent Events and Trainings

Watch Now!
Authentically Mediterranean: Discover Celestyal’s New Western Mediterranean Itineraries & Iconic ClassicsTuesday, July 21, 2026
2:00pm Eastern
The Mediterranean is more than just a destination, it’s our home. Join Celestyal to learn why we are...
Watch Now!
July The Travel Corporation WebinarTuesday, July 21, 2026
2:00pm Eastern
Save your spot for this upcoming webinar! Details coming soon!
Upcoming Webinar
Sani/Ikos Group: Luxury Beachfront Resorts in Greece & SpainTuesday, July 28, 2026
2:00pm Eastern
Join us for an exclusive webinar introducing Sani/Ikos Group, a collection of luxury beachfront...
Watch Now!
Authentically Mediterranean: Discover Celestyal’s New Western Mediterranean Itineraries & Iconic ClassicsTuesday, July 21, 2026
2:00pm Eastern
The Mediterranean is more than just a destination, it’s our home. Join Celestyal to learn why we are...
Watch Now!
July The Travel Corporation WebinarTuesday, July 21, 2026
2:00pm Eastern
Save your spot for this upcoming webinar! Details coming soon!
Upcoming Webinar
Sani/Ikos Group: Luxury Beachfront Resorts in Greece & SpainTuesday, July 28, 2026
2:00pm Eastern
Join us for an exclusive webinar introducing Sani/Ikos Group, a collection of luxury beachfront...