Hospitality in the Cyber Crosshairs

August 11, 2026

Peak season does not only bring more guests. It also brings more identities, devices, transactions and third-party access. For hotel security teams, the challenge is increasingly one of deciding whom — and what — to trust.

A fully booked hotel is a commercial success. From a cyber security perspective, however, peak occupancy also means peak digital activity. More reservations are processed, more payments are handled, more devices connect to networks and more employees require access to operational systems. Permanent staff work alongside seasonal employees, contractors and external service providers, all of whom may need access to property-management systems, booking platforms, payment services, cloud applications or network infrastructure.

The result is not necessarily a more vulnerable individual system. It is a more complex environment in which identities, permissions and trusted relationships multiply rapidly.

WatchGuard Technologies has warned that this makes the hospitality sector particularly exposed to identity-based attacks during periods of high demand. Its 2026 Employee Cybersecurity Hygiene Report, based on responses from 684 employees worldwide and across industries, highlights the behavioural side of the problem: 76 per cent of respondents admitted reusing passwords across multiple accounts, while 70 per cent used public Wi-Fi for work-related activities. Twenty-three per cent said they had never received phishing training, and WatchGuard calculates that 71 per cent receive such training no more than once a year, if at all.

For hospitality businesses, these practices meet an unusually fragmented technology landscape. Property-management systems, revenue and reservation platforms, point-of-sale environments, loyalty programmes, guest portals and cloud services are frequently interconnected. Access may be required by front-desk staff, housekeeping, catering, maintenance teams, outsourced IT providers and payment partners. During the holiday season, temporary employees may be added for only a few weeks or months.

Every one of those users represents another identity that must be created, authenticated, authorised, monitored and eventually removed.

Attacks That Look Like Business as Usual

The most effective hospitality attacks increasingly exploit precisely this operational reality. Rather than relying on obviously suspicious messages, attackers replicate the communications that hotel employees expect to receive every day.

Microsoft Threat Intelligence has documented an international phishing campaign in which attackers impersonated Booking.com and targeted hospitality organisations. The lures were closely aligned with normal hotel operations: alleged negative reviews, questions from prospective guests, advertising proposals or requests to verify a Booking.com account.

Victims were directed to pages designed to resemble legitimate services. In some cases, attackers used the social-engineering technique known as ClickFix, persuading users to perform what appeared to be a security verification while in reality executing commands on their own computers. Microsoft subsequently observed malware including XWorm, Lumma Stealer, VenomRAT, AsyncRAT and Danabot, with capabilities ranging from credential theft to the collection of financial and other sensitive information.

A further campaign observed by Microsoft from April 2026 demonstrated how closely threat actors can tailor their activity to hospitality workflows. Hotels in Europe and Asia received messages concerning alleged guest complaints and room enquiries. Attackers also abused legitimate services including Calendly and Google URL redirects to make malicious communications appear more trustworthy.

The payload arrived in ZIP archives supposedly containing photographs. In reality, the files included disguised Windows shortcuts that initiated a multi-stage infection chain involving obfuscated PowerShell and a Node.js-based implant capable of establishing persistent access.

The specific malware matters less than the attack model. Reception and reservation staff are expected to open links, investigate guest complaints, inspect attachments and react quickly to booking problems. Attackers do not have to circumvent those processes. They simply make them part of the intrusion chain.

That distinction matters during peak season, when workload and response pressure are highest.

When the Guest Network Becomes the Attack Platform

An even more consequential development emerged with the campaign Microsoft disclosed in July 2026 under the name CaptiveCrunch. Here, the hotel employee was not necessarily the primary target. Hospitality infrastructure itself was used to attack guests.

Microsoft observed the manipulation of captive portals — the login pages travellers encounter before gaining access to hotel or conference Wi-Fi. Attackers were able to interfere with DNS and HTTP traffic inside compromised environments and redirect users through attacker-controlled infrastructure. Techniques included fraudulent Microsoft login pages, adversary-in-the-middle attacks and fake browser or operating-system updates.

The malware used in the operation was capable of stealing credentials and session tokens, recording keystrokes and files, and enabling audio or video surveillance. Microsoft identified compromised hospitality networks in several countries and assessed business travellers as particularly attractive targets.

This changes the way hotels need to think about guest Wi-Fi.

Network separation between guest and corporate systems remains essential, but segmentation alone does not address the full risk. A compromised captive portal can facilitate a serious attack without an intruder ever gaining access to the hotel’s property-management system. The property instead becomes a trusted intermediary in an attack against its guests — potentially including executives and employees carrying privileged access to organisations far beyond the hotel itself.

The initial compromise mechanism in the CaptiveCrunch cases has not yet been conclusively established. Microsoft did, however, identify similarities in devices and management systems used across some affected networks, raising the possibility that shared services within the captive-portal ecosystem could have played a role.

For security leaders, that points to a wider problem. A hotel may secure its immediate network responsibly and still be exposed through an external Wi-Fi platform, reservation provider, cloud service, payment processor or other supplier.

Hospitality cyber security is therefore increasingly dependent on the security maturity of organisations outside the hotel itself.

AI Accelerates an Existing Problem

Artificial intelligence adds another layer, although it is important not to overstate the change. AI did not invent phishing, credential theft or social engineering. What it can do is reduce the cost of conducting them.

Publicly available information about potential victims can be analysed more rapidly, messages adapted more convincingly and large-scale campaigns personalised with far less manual effort. Language is also becoming less of a barrier, which matters for an industry that operates across borders, languages and national markets.

WatchGuard also points to a parallel internal risk. In its employee survey, 64 per cent of respondents said they use unauthorised AI tools for work. This extends the familiar problem of shadow IT into what is increasingly described as shadow AI: employees may place company information into tools operating outside approved security, privacy and compliance controls.

Microsoft has also observed AI being used in support of parts of the CaptiveCrunch operation. The more significant shift is therefore not the arrival of an entirely new category of attack, but the industrialisation of existing techniques. Target research, social engineering and parts of the attack lifecycle can increasingly be conducted faster and at greater scale.

Identity, however, must not become the sole focus. Verizon’s 2026 Data Breach Investigations Report provides an important counterweight. Exploitation of vulnerabilities accounted for 31 per cent of initial access in the breaches analysed, overtaking stolen credentials as the leading entry point. Ransomware was associated with almost half of the breaches examined.

For hotels, the conclusion is straightforward: identity protection, patch management, endpoint security, segmentation and third-party risk management have to be treated as one security programme, not as competing priorities.

A Password Is No Longer Sufficient Proof of Trust

This is particularly important in an industry where people, devices and systems are constantly moving.

A successfully entered password proves little more than the fact that somebody knows the password. It does not establish that the person behind the login is the legitimate user.

Multi-factor authentication should therefore be a baseline requirement for business-critical and privileged accounts. Where the potential impact is high, phishing-resistant authentication deserves particular attention. Current guidance from the US National Institute of Standards and Technology stresses the limitations of passwords and authentication mechanisms that can themselves be captured through phishing, pointing instead towards cryptographic and phishing-resistant approaches such as passkeys and hardware-backed authenticators for higher-assurance use cases.

For hospitality operators, the principle is especially relevant to administrator accounts controlling property-management systems, network infrastructure, payment environments and cloud platforms.

Seasonal staffing also requires more disciplined access governance. Temporary access should be temporary by design. Accounts should be limited to the systems required for a particular role, granted only for the necessary period and removed promptly when employment ends. A seasonal employee who left months ago should not remain a valid identity in the environment.

This is where Zero Trust becomes more useful as an operating principle than as a marketing term. Access should not be considered safe merely because a password is correct, a device appears to be internal or a request originates from a familiar network. Identity, device posture, context and the sensitivity of the requested resource all need to contribute to the decision.

For hospitality, with its mixture of temporary employees, contractors, cloud applications and external partners, that approach is particularly well suited to the reality of the business.

Peak Season Needs Its Own Security Readiness Check

The practical lesson is that cyber readiness should become part of seasonal operational planning.

Hotels routinely prepare staffing levels, catering capacity, room availability and physical facilities before periods of high demand. Identity and cyber security deserve the same treatment.

Before peak season begins, operators should review user accounts and privileges, remove obsolete access, establish tightly defined roles for temporary employees and verify stronger authentication on privileged systems. Guest Wi-Fi and captive portals should be treated as production infrastructure, with clear responsibilities for patching, monitoring, administrative access and incident response — including where those services are outsourced.

Supplier access deserves the same attention. Hotels need to know who administers their externally provided platforms, how privileged credentials are protected, how vulnerabilities are handled and what happens when compromise is suspected. The security of a hotel’s technology stack is increasingly inseparable from the security of its suppliers.

Security awareness also needs to become operational rather than generic. An annual presentation on phishing will have limited value if real attacks arrive as convincing room enquiries, Booking.com notifications, guest complaints or photographs supposedly sent by a customer. Exercises should reflect what reception, reservations, finance and management teams actually encounter.

The current campaigns reveal an uncomfortable truth: attackers increasingly understand the workflows of hospitality organisations very well. Defenders need to understand them at least as well.

The objective should not be to burden staff with so many warnings and confirmation steps that normal service becomes impossible. The objective is to design controls around the way hotels actually operate, ensuring that a stolen password, a single mistaken click or a compromised supplier cannot automatically provide access to the next system in the chain.

Peak season does not make a hotel inherently insecure. It amplifies the characteristics attackers find useful: more users, more temporary access, more external partners, more devices and more digital interactions taking place under greater time pressure.

For security leaders across the EMEA hospitality sector, this makes identity governance, phishing-resistant authentication, effective offboarding, network segmentation and third-party assurance seasonal operational priorities rather than back-office IT concerns.

Hotels are built around trust. Guests trust staff, employees trust booking platforms, companies trust hotel networks and operators trust their technology providers.

Cyber security increasingly depends on ensuring that none of those relationships is trusted simply because it looks familiar.

[ML]

Related Articles

Germany’s Security Paradox: Excellent at Rules, Slow at Results

Viewed from outside, Germany presents a curious contradiction. Few countries take standards, procedures and institutional safeguards more seriously. Yet in security, infrastructure and public administration, the machinery designed to prevent mistakes can itself become...

Drone defence starts with situational awareness

From power plants and airports to logistics hubs and industrial sites, Europe’s critical infrastructure is facing a new security dimension above the conventional perimeter. A visit by former German Federal Transport Minister Patrick Schnieder to LivEye’s Drone...

Share This