Gadget Bridge
HomeNewsTwo in three hotel websites leak guest booking details: Symentec researcher

Two in three hotel websites leak guest booking details: Symentec researcher

Are you planning to go on a vacation? Do make sure that you pick the right hotel or else you may have your information leaked. A Principal Threat Researcher at cybersecurity company Symantec, Candid Wueest, recently tested websites of 1,500 hotels in 54 countries to understand how many of these could potentially leak the personal data of guests staying at their property.

The results of the research were shocking. Wueest found out that around 67 percent or two in three of the websites that he studied inadvertently leaked the booking codes to other third-party websites. The information is also being shared with advertisers and analytics companies.

We should add here that the websites that Wueest tested included two-star hotels located in the countryside, as well as luxurious five-star resorts. Speaking about this, Wueest said, “Basically, I randomly chose locations where I would like to spend my vacation, then selected the top search engine results for hotels in those locations. Some hotel sites I tested are part of larger, well-known hotel chains, meaning my research for one hotel applies to other hotels in the chain.”

- Advertisement -

According to Wueest, a number of the websites that he studied disclosed personal data like full name, email, address, postal code mobile number, last four digits of credit card, card type, and expiration date and even the passport number. The leak of so much information is very shocking.

Wueest explained the matter in more detail saying, “More than half (57 percent) of the sites I tested send a confirmation email to customers with a direct access link to their booking. This is provided for the convenience of the customer, allowing them to simply click on the link and go straight to their reservation without having to log in.”

It is worth noticing that since the email requires a static link, HTTP POST web requests are not really an option. This basically means that the booking reference code and the email are passed as arguments in the URL itself. We should point out that on its own, this would not be an issue. However, a number of sites directly load additional content like advertisements on the same website.

This means that direct access is shared with other resources. At times it is done directly, however, at other times is it done indirectly through the referrer field in the HTTP request.

- Advertisement -

According to Wueest, his tests show that an average of 176 requests are generated per booking, although not all these requests contain the booking details. We must add here that going by the number, it can be concluded that the booking data could be shared quite widely.

Furthermore, it has also been revealed that the booking data is also available when the customer cancels the reservation. The research also indicates that hotel comparison websites and booking engines also leak customers’ data. Wueest said, “From the five services that I tested, two leaked the credentials and one sent the login link without encryption.”

For the latest gadget and tech news, and gadget reviews, follow us on TwitterFacebook and Instagram. For newest tech & gadget videos subscribe to our YouTube Channel. You can also stay up to date using the Gadget Bridge Android App.

Support Us

We are a humble media site trying to survive! As you know we are not placing any article, even the feature stories behind any paywall or subscription model. Help us stay afloat, support with whatever you can!

Support us
- Advertisement -
Gadget Bridge Bureau
Gadget Bridge Bureauhttp://gadgetbridge.com
Team Gadget Bridge is your ultimate source for all things electronic. Our comprehensive coverage spans the latest gadgets, breaking tech news, insightful how-to guides, the business behind technology, enterprise-level tech solutions, and emerging careers in the tech industry. We're committed to bringing you the most up-to-date and in-depth technology news from around the globe, with the aim of being your go-to destination for tech insights and updates.
- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisement -

Latest From Gadget Bridge

Volleyball Legends Codes (September 2025)

If you’re a fan of the anime series Haikyuu, you cannot miss its Roblox adaptation. Previously known as...
- Advertisement -

Latest Reviews

Lava Blaze Dragon 5G Review: The budget smartphone that breathes fire

Lava’s newest entry-level offering is priced at Rs 10,000. At this price point, it faces tough competition from...
- Advertisement -

Tech How To

How to create a calling card in Google Contacts

Google's new facelift for its Phone app hasn’t gone down well with its users. However, the Contacts app...
- Advertisement -