hotelvak.eu
EN
Platform on hotelmanagement, interiordesign and design in the Netherlands
Has your hotel been hacked? Unplug the internet cable, but don’t switch anything off
Ethical hacker Sergen Koç explains how hackers think.

Has your hotel been hacked? Unplug the internet cable, but don’t switch anything off

Ethical hacker Sergen Koç warns hotels: ‘Know which digital doors are open, who has the keys and who will take action if things go wrong’

Hotels thrive on hospitality, trust and convenience. Guests book online, check in digitally, are increasingly using an app to unlock their rooms, use Wi-Fi, pay online and expect everything to run smoothly. Behind that seamless guest journey lies a complex digital network of booking platforms, property management systems, channel managers, point-of-sale systems, cameras, telephones, smart TVs, digital keys and supplier portals.

According to ethical hacker Sergen Koç, that is precisely where the vulnerability lies. “The more systems that are accessible via the internet, the more digital entry points there are. And hackers don’t start by checking whether a hotel is large or small. They scan the internet for systems that are open or poorly secured. If they find something, they try to break in.”

Has your hotel been hacked? Unplug the internet cable, but don’t switch anything off 1
The more systems that are accessible via the internet, the more digital entry points are created.

Expert

Koç knows what he’s talking about. The Dutch cybersecurity specialist is the founder of Hacker B.V., a company that specialises in offensive security, cyberwarfare and penetration testing. In other words: Koç and his team think and work like hackers, but on behalf of companies and government bodies that want to know where their vulnerabilities lie before criminals discover them.

His name now features in the Hall of Fame of organisations including the National Police, OV-chipkaart, Achmea, KPN, Nokia, Apple, VPRO and the Royal Netherlands Academy of Arts and Sciences. He has also identified vulnerabilities at institutions including Harvard University. Koç gained national recognition after discovering a serious vulnerability in Apple’s software. Through Apple’s bug bounty programme, he received a reward of 50,000 euros for this.

His path into cybersecurity was an unusual one. Koç studied artificial intelligence and began his career at the travel company TUI as a network and security engineer. Following a major security incident, at the age of 25 he wrote a comprehensive contingency plan to guide the organisation through such a crisis. Shortly afterwards, he became Information Security Officer for TUI Netherlands, with a budget running into millions to improve cybersecurity across offices, travel agencies, aeroplanes and cruise ships. During the pandemic, he taught himself how to hack – not to cause damage, but to better understand how attackers think. “If I know how hackers get in, I also know how to keep them out.”

Target

For hotels, this knowledge is more relevant than ever. The sector has featured in the news on several occasions in recent months for negative reasons, due to data breaches and stolen booking information. According to Koç, this is no coincidence. Hotels hold a combination of data that is particularly valuable to criminals: names, email addresses, telephone numbers, dates of stay, booking numbers, payment details, billing addresses, information about travel groups and sometimes even copies of passports. “With that information, you can carry out very convincing phishing attacks,” says Koç. “If a criminal knows exactly when someone is arriving, which hotel they are staying at and the corresponding booking number, then a fake payment request suddenly seems very genuine. That’s what makes it dangerous.”

Entrances

What’s more, hotels are, by their very nature, service-oriented. Staff want to help guests. They resolve problems, resend payment requests, amend bookings and answer enquiries via email, telephone or at reception. That instinct to be hospitable is a strength, but it can also become a weakness – particularly when staff are not sufficiently trained to recognise suspicious requests.

According to Koç, a hacker usually doesn’t start from the inside, but from the outside. “What’s visible from the internet? Login pages, supplier portals, email settings, forgotten servers, remote management systems. Is anything configured incorrectly there? Are weak passwords being used? Can you send an email that looks as if it’s genuinely from the hotel? Those are the first things you look at.”

He notices a striking number of digital access points at hotels. PMS systems, booking platforms, channel managers, cameras accessible via the internet, smart TVs, telephones and Wi-Fi networks. Security has often been considered, but not always from an attacker’s perspective. This also applies to new technology, such as digital room keys. “I assume that suppliers take security into account. But the question is: has it also been tested by someone who thinks like a hacker? Can you take an app apart, reverse-engineer it and understand how that key is retrieved or presented at the door? Those are the scenarios you need to test.”

Wi-Fi

Hotel Wi-Fi also remains a cause for concern. Koç notes that many hotels have now set up their networks more effectively, but still comes across examples where the separation isn’t good enough. In one hotel where he stayed, he was able to access other rooms on the same floor from his own room. “In theory, you could have made all the phones ring at once. Of course, I didn’t do that, but it shows that the separation wasn’t properly configured. In this case, it might just be annoying, but the same mistake could have much more serious consequences in a different system.”

Human

Another vulnerability lies with staff. Hotels operate with rotating shifts, temporary staff and seasonal workers. Accounts sometimes remain active after someone has left. Alternatively, shared accounts are used because it is quicker and easier.

“I understand why that happens,” says Koç. “If someone is only coming to help out for a week, you don’t want to set everything up separately for everyone. But a shared account usually requires an easy-to-remember password. And if nobody knows exactly who did what, it also becomes much harder to spot any misuse.”

Has your hotel been hacked? Unplug the internet cable, but don’t switch anything off 2
Koç: ‘Hackers don’t check first whether a hotel is large or small.’.

Impact

According to Koç, the idea that large hotel chains are the main targets for criminals is incorrect. In fact, smaller hotels can actually be hit harder. “Hackers don’t think: ”Which hotel shall I attack today?’ They use automated tools to scan the internet. If a small hotel with a vulnerable system turns up, that’s just as interesting. For a criminal, every euro counts.”

The impact may be greater for smaller hotels, as they are often more reliant on a few digital systems and have fewer fallback options. Large chains usually have IT teams, crisis procedures and alternative processes in place. A smaller hotel is more likely to have to rely on external help. If the PMS isn’t working, bookings can’t be viewed and payments are held up, operations come under pressure almost immediately. “It’s not just about data,” says Koç. “Your business comes to a standstill.”

Incident

What should a hotel do if it suspects it has been broken into? Koç is clear: disconnect the internet, but do not switch off the systems.

“Do not switch off any computers or servers, and do not touch anything. Unplug the internet cable. If necessary, cut it. This will limit the damage, as a hacker will be unable to continue downloading or moving around the network. However, the systems must remain switched on for the investigation.”

The next step is to establish what has happened, where the attacker gained access and which data has been compromised. A cyber insurance policy can assist with a checklist, reporting the incident to the Dutch Data Protection Authority, filing a police report and engaging IT forensic specialists. It is also essential to check whether the attacker has left a backdoor. “You might seal off the initial point of entry, but someone could gain access again in three months” time via something that was left behind earlier.”

Has your hotel been hacked? Unplug the internet cable, but don’t switch anything off 3
Although most hotels back up their systems, hardly anyone checks whether you can actually restore them.

Prevention

That is why Koç advocates an incident plan that is not only drawn up once things have gone wrong. A hotel operates 24 hours a day. So even at three o’clock in the morning, it must be clear who is to be contacted, who makes the decisions and what steps are to be taken.

“Who is responsible? Who knows what to do? Who is authorised to disconnect systems? Who contacts the IT supplier? You need to sort that out in advance.”

There is some good news, too. Hotels do not need a budget running into millions to take the first major steps. According to Koç, cybersecurity starts with a clear overview and a sense of responsibility.

“Know which digital doors are open. Know who has the keys. And know who will take action if a door turns out to be open.”

In practical terms, this means: enable two-factor authentication for email, booking systems and important accounts. Ask suppliers whether systems such as PMS, booking modules and digital keys have been independently tested. La

Demonstrate that the guest network is genuinely separate from internal systems. Train staff, including temporary staff, to recognise phishing attempts and suspicious requests. Avoid shared accounts. Ensure that bank account numbers or large payments can never be altered by a single person or from a single hacked account.

Back-up

And don’t forget to back up your data. Many companies make backups, but never test whether they can actually restore them.

“I see that every day,” says Koç. “On paper, there’s a backup. But when things go wrong, it turns out that nobody knows how to restore it, or that the backup doesn’t work. Test it at least once a year.”

For hotel owners and operations managers, the message is therefore as simple as it is uncomfortable. Cybersecurity is no longer just an IT issue. It is part of hospitality, business continuity and trust. A guest who provides their details to a hotel trusts that they will be handled with care. If that trust is breached, it directly damages the hotel’s reputation.

“Everything in our society revolves around trust,” says Koç. “If that trust disappears, you no longer have a business.”

CHECKLIST FOR HOTELS:
CHECK IT TODAY

  • Is two-factor authentication enabled for email, the PMS, booking accounts and administrator accounts?
  • Do you know which systems can be accessed via the internet?
  • Are the guest Wi-Fi and internal systems demonstrably separate?
  • Are temporary staff members added with their own accounts and then removed again?
  • Are shared accounts and easy-to-guess passwords out of the question?
  • Is it clear who should be phoned in the event of a hack at three o’clock in the morning?
  • Is there an incident response plan in place for data breaches, ransomware and system failures?
  • Have the PMS, booking system and digital key solution provider portals been tested?
  • Can’t anyone change their bank details or make large payments on their own?
  • Is a test carried out at least once a year to check whether backups can actually be restored?

"*" geeft vereiste velden aan

Dit veld is bedoeld voor validatiedoeleinden en moet niet worden gewijzigd.

Send us a message

Wij gebruiken cookies. Daarmee analyseren we het gebruik van de website en verbeteren we het gebruiksgemak.

Details

Kunnen we je helpen met zoeken?

Bekijk alle resultaten