Holiday Inn Parent Company Hacked Through Weak Password

Holiday Inn Ihg Hacked Featured

If you’ve wondered why having a strong password is necessary, this recent trouble is the reason. Intercontinental Hotels Group, the parent company of the Holiday Inn and other hotel chains, was hacked, and a Vietnamese couple is claiming responsibility for deleting the chain’s data, saying they did it through a week password.

Also read: How to Make Mobile Safari Save Your Passwords on iOS

ICG Trouble

Customers of Intercontinental Hotels Group (ICG) first started reporting errors booking rooms and checking in on September 5. IHG responded on social media and said it was “undergoing system maintenance.”

The hotel chain released an announcement to investors on September 6 that said part of its system had been “subject to unauthorized activity.” It reported that the booking channels and other applications had been disrupted since the day before.

Holiday Inn Ihg Hacked Booking Website

ICG said it reacted to the hack by putting into play its response plans and notifying the authorities, adding that it was working on the issue with tech specialists. ICG also said it was supporting hotel owners and operators and that its hotels were still operating and taking reservations.

Couple Claims Responsibility for Hack

A Vietnamese couple came forward and admitted to the BBC that they were behind the ICG cyberattack, yet deleting a large amount of data wasn’t the original plan. Initially, the plan was to launch a ransomware attack after they gained access to the company’s databases through a very weak password: “Qwerty1234.”

The couple, going by the name of TeaPea, reached the BBC through Telegram and supplied screenshots, which IHG confirmed were authentic, that showed them gaining access to ICG’s Outlook emails, Microsoft Teams chats, and server directories.

Holiday Inn Ihg Hacked Data
Image source: Unsplash

The hackers explained, “Our attack was originally planned to be a ransomware, but the company’s IT team kept isolating servers before we had a chance to deploy it, so we thought to have some funny [sic]. We did a wiper attack instead.”

TeaPea also claimed that they only make about $300 monthly, so they don’t feel guilty doing something illegal. They don’t believe their actions hurt the hotels that much. No customer data was removed from the services.

They were able to access the internal IT network at IHG through malicious software that an unknowing employee downloaded from an email. It was also able to break through the company’s 2FA system. Once inside the server, they found the login details for the internal password vault.

ICG Systems Returning to Normal

ICG reported afterward that while the services of Holiday Inn and its other services were still being interrupted, the systems were returning to normal after they were hacked.

Holiday Inn Ihg Hacked Password
Image source: Wikimedia Commons

The hotel chain’s spokeswoman defended its security practices, stating that for hackers to get through to its systems, they had to get past “multiple layers of security,” adding, “IHG employs a defense-in-depth strategy to information security that leverages many modern security solutions.”

But the point remains: there is a weakness somewhere within the systems of Holiday Inn and the other hotel chains for the sensitive information to be hacked. “Qwerty1234” appears on lists of common passwords and isn’t safe to use. Additionally, while it does have lower and uppercase letters and numbers, it does not have any symbols. If IHG did use that as a password, it was not a “defense-in-depth strategy.”

Image credit: Wikimedia Commons All screenshots by Laura Tucker

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
Octopuses possess roughly 500 million neurons distributed across their body, with two-thirds located in their arms rather than their central brain, meaning each arm can taste, problem-solve, and react to stimuli independently of whatever the octopus is otherwise paying attention to.
The Roman aqueduct at Segovia, built around the first century AD without mortar, still carried water into the 1970s, its 167 granite arches held together by nothing but the precise weight distribution of stones cut to fit each other within fractions of a millimeter.
When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use