Holiday Inn Parent Company Hacked Through Weak Password

Holiday Inn Ihg Hacked Featured

If you’ve wondered why having a strong password is necessary, this recent trouble is the reason. Intercontinental Hotels Group, the parent company of the Holiday Inn and other hotel chains, was hacked, and a Vietnamese couple is claiming responsibility for deleting the chain’s data, saying they did it through a week password.

Also read: How to Make Mobile Safari Save Your Passwords on iOS

ICG Trouble

Customers of Intercontinental Hotels Group (ICG) first started reporting errors booking rooms and checking in on September 5. IHG responded on social media and said it was “undergoing system maintenance.”

The hotel chain released an announcement to investors on September 6 that said part of its system had been “subject to unauthorized activity.” It reported that the booking channels and other applications had been disrupted since the day before.

Holiday Inn Ihg Hacked Booking Website

ICG said it reacted to the hack by putting into play its response plans and notifying the authorities, adding that it was working on the issue with tech specialists. ICG also said it was supporting hotel owners and operators and that its hotels were still operating and taking reservations.

Couple Claims Responsibility for Hack

A Vietnamese couple came forward and admitted to the BBC that they were behind the ICG cyberattack, yet deleting a large amount of data wasn’t the original plan. Initially, the plan was to launch a ransomware attack after they gained access to the company’s databases through a very weak password: “Qwerty1234.”

The couple, going by the name of TeaPea, reached the BBC through Telegram and supplied screenshots, which IHG confirmed were authentic, that showed them gaining access to ICG’s Outlook emails, Microsoft Teams chats, and server directories.

Holiday Inn Ihg Hacked Data
Image source: Unsplash

The hackers explained, “Our attack was originally planned to be a ransomware, but the company’s IT team kept isolating servers before we had a chance to deploy it, so we thought to have some funny [sic]. We did a wiper attack instead.”

TeaPea also claimed that they only make about $300 monthly, so they don’t feel guilty doing something illegal. They don’t believe their actions hurt the hotels that much. No customer data was removed from the services.

They were able to access the internal IT network at IHG through malicious software that an unknowing employee downloaded from an email. It was also able to break through the company’s 2FA system. Once inside the server, they found the login details for the internal password vault.

ICG Systems Returning to Normal

ICG reported afterward that while the services of Holiday Inn and its other services were still being interrupted, the systems were returning to normal after they were hacked.

Holiday Inn Ihg Hacked Password
Image source: Wikimedia Commons

The hotel chain’s spokeswoman defended its security practices, stating that for hackers to get through to its systems, they had to get past “multiple layers of security,” adding, “IHG employs a defense-in-depth strategy to information security that leverages many modern security solutions.”

But the point remains: there is a weakness somewhere within the systems of Holiday Inn and the other hotel chains for the sensitive information to be hacked. “Qwerty1234” appears on lists of common passwords and isn’t safe to use. Additionally, while it does have lower and uppercase letters and numbers, it does not have any symbols. If IHG did use that as a password, it was not a “defense-in-depth strategy.”

Image credit: Wikimedia Commons All screenshots by Laura Tucker

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.