Hotels too often leave people vulnerable to identity theft

  • Friday, April 19, 2013 6:40pm
  • Life

Several days after Traci Fox visited a small independent resort in the Catskill Mountains, she received an unexpected call from a shoe store.

Where did she want it to ship the $400 worth of pricey sneakers that she’d ordered?

Just one problem: She hadn’t purchased any footwear. As Fox, a college professor from Philadelphia, Pa., rummaged through her pocketbook to find her credit card, the phone rang again.

“It was Coach handbags asking if I wanted the $750 worth of handbags shipped to a different address,” she says.

Calls to her credit card revealed another bogus charge for $7,500 at Home Depot.

“Of course, I wasn’t liable for anything,” she said. “But it was still scary and frustrating.”

Fox believes that her hotel may have compromised her credit card information. At least one government agency shares her concerns.

Last summer, the Federal Trade Commission sued Wyndham Hotels, alleging that the company had failed to protect its customers’ personal information.

As a result, the FTC claims, hundreds of thousands of credit card numbers fell into the wrong hands, leading to millions of dollars in fraud-related losses. Wyndham denies any wrongdoing and is fighting the suit.

“Data security is becoming an issue of significant importance in the hospitality industry,” said Mark Schreiber, an attorney specializing in hospitality law at the Boston firm of Edwards Wildman Palmer.

He cited an increase in hacks and malware attacks, which frequently target hotel systems because they’re a rich source of personal information.

Identity theft expert John Sileo said that there’s another reason hotel guests are vulnerable to having their personal information stolen: They’re easily distracted.

“We just don’t pay attention to the details when we’re running through airports and staying in unfamiliar places,” he said. “It’s easier to miss something and to be careless.”

Data breaches can happen anywhere within a hotel. Ann Azevedo, an engineer who lives in Hartford, Conn., checked out of a chain hotel in Seattle not long ago.

A few days later, someone used her card to buy gas on the other side of the country, she says. The likely source of the breach was an ATM machine at the hotel.

“I canceled the credit card,” she said. “And I’ll never use a hotel ATM again.”

Data privacy expert Edward Hasbrouck said, “Credit card theft is much easier — and more likely — through large-scale hacking,” he said.

In the FTC’s lawsuit, for example, the agency alleges that Wyndham failed to take security measures such as requiring employees to generate complex user IDs and passwords and to properly install firewalls and network segmentation between the hotels and the corporate network, according to the agency.

It’s difficult to take preventive steps, say experts. Apart from paying with cash, there’s almost no way to tell whether a hotel will treat your personal information with care or whether it will leave a backdoor or firewall unguarded for hackers to steal your credit card information.

Large hotel chains will post their data protection policies online, “but they won’t make much sense to the average consumer,” said Richard Alderman, who directs the Center for Consumer Law at the University of Houston Law Center.

“I think consumers should continue to deal with hotels as they have in the past, knowing that almost all hotels are as concerned with customers’ privacy as are the customers,” he added.

The problem may run deeper than the theft of credit card numbers, however.

The personally identifiable information in your guest profile, such as your home address, your license plate number and your date of birth, which is attached to your reservation, can end up in the hands of a third party that offers little or no warranties about how it will protect your data.

Apart from having the hotel industry tighten security, the best way to address data theft may be through changes in consumer law.

A good starting point might be to tell consumers what information is being collected from them and passed along to third parties, Hasbrouck said.

“Most travelers would be shocked to know how many other companies the hotel may have given (the information) to in the normal course of their business,” Hasbrouck said.

Christopher Elliott is the ombudsman for National Geographic Traveler magazine and the author of “Scammed.” Read more travel tips on his blog, www.elliott.org or email him at celliott@ngs.org.

&Copy; 2013 Christopher Elliott/ Tribune Media Services, Inc.

More in Life

Hear new songs from Josh Clauson at Saturday release party

The producer of the Summer Meltdown music festival and Flowmotion band leader has a solo album out.

Get schooled on Texas BBQ at this Monroe restaurant in a bus

Brisket, pulled pork, sausage, chicken and the fixin’s all await you near the Reptile Zoo on U.S. 2.

Spy comedy ’Kingsman: The Golden Circle’ is laugh-out-loud funny

It’s a superficial but energetic sequel to the 2014 film about a clandestine British secret service.

39th annual Arts of the Terrace attracts regional artists

The Mountlake Terrace juried show features paintings, drawings, photography, miniatures and more.

Ben Stiller was born to play title character in ‘Brad’s Status’

Writer-director Mike White’s script has plenty of Brad’s voiceover, so this movie feels like a novel.

See both versions of ‘The Odd Couple’ on Historic Everett stage

The Outcast Players perform Neil Simon’s classic comedy with alternating male and female casts.

The ‘Whimsical Woman’ shares what she learns on the trail

Jennifer Mabus came here from Nevada and Hawaii. She leads hikes and blogs about them.

‘Friend Request’ a horror flick about the dangers of Facebook

Though it’s a little behind the times, Simon Verhoeven’s film about social media is effectively done.

Branch out: ‘Tasting Cider’ recipes call for hard apple cider

Top cider makers share how they like to make hush puppies, bread pudding and the pear-fect cocktail.

Most Read