Cybersecurity: Google hit by hacking of Sabre system

A flaw in the cyber security of the SynXis CRS system supplied by Sabre has led to the leak of the personal information of Google's business travellers, whose business trips are managed by CWT.
Google
The Google Googleplex campus

Cyber security issues are more than ever at the heart of the debate, as large-scale attacks multiply. A few weeks ago, the WannaCry ransomware had already underlined the urgency of the situation, striking on a global scale. This time, three of the biggest names in business travel and new travel-related technologies are more or less directly affected by hacking: the employee data of Googlewhose business travel is managed by CWTs SynXis system was hacked and leaked. Sabre Hospitality. Sabre reported the problem to TMC, which alerted its flagship client on 16 June, as indicated in a document distributed by Google to its employees: " Sabre has informed CWT, which uses the SynXis CRS system, that an unauthorized third party has gained access to personal information associated with certain hotel reservations via CWT "Google explains to its employees, indicating that it is working with the two partners to identify the business travellers concerned.

The nature of the information involved, and above all the duration of the leak, is prompting Google to exercise caution. The intrusion is believed to have targeted " the name, contact details and details of the payment card used for certain hotel reservations in the SynXis CRS system between 10 August 2016 and 9 March 2017" . He added: " Sabre's investigation found no evidence of access to information such as Social Security, passport or driving licence numbers" . But the players involved are still unsure...

Sabre has entrusted the investigation to one of the leaders in the field of cybersecurity, while Google has decided to offer its employees a two-year subscription to complementary identity protection and banking surveillance services provided by AllClear ID. For its part, the business travel agency is refusing to accept responsibility for the breach in a third-party system, which it does not use : " CWT has been informed by Sabre that passenger data has been consulted by external parties following a breach in their system " Hospitality Solutions / SynXis Central Reservation "("SHS"), which provides reservation technology and support to hotels" says TMC. " SHS is not a CWT technology platform nor a solution used by CWT" says Carlson Wagonlit Travel.

For a number of years now, the various players in the business travel industry have been investing in personalising their offer: a logic which, without optimum security for all the links in the business travel chain, can unfortunately prove dangerous for the business traveller and his company.