Business & Finance

IHG Notifies Guests of Payment Card Incident at IHG-Branded Franchise Hotel Locations in the Americas Region

ATLANTA, GA. April 18, 2017 - IHG values the relationship it has with its guests and understands the importance of protecting payment card data. Many IHG-branded locations are independently owned and operated franchises, and certain of these franchisee operated locations in the Americas were made aware by payment card networks of patterns of unauthorized charges occurring on payment cards after they were legitimately used at their locations. To ensure an efficient and effective response, IHG hired a leading cyber security firm on behalf of franchisees to coordinate an examination of the payment card processing systems of franchise hotel locations in the Americas region.

The investigation identified signs of the operation of malware designed to access payment card data from cards used onsite at the front desk at certain IHG-branded franchise hotel locations between September 29, 2016 and December 29, 2016. Although there is no evidence of unauthorized access to payment card data after December 29, 2016, confirmation that the malware was eradicated did not occur until the properties were investigated in February and March 2017. Before this incident began, many IHG-branded franchise hotel locations had implemented IHG's Secure Payment Solution (SPS), a point-to-point encryption payment acceptance solution. Properties that had implemented SPS before September 29, 2016 were not affected. Many more properties implemented SPS after September 29, 2016, and the implementation of SPS ended the ability of the malware to find payment card data and, therefore, cards used at these locations after SPS implementation were not affected.

The malware searched for track data (which sometimes has cardholder name in addition to card number, expiration date, and internal verification code) read from the magnetic stripe of a payment card as it was being routed through the affected hotel server. There is no indication that other guest information was affected. A list of affected franchise locations and respective time frames, which may vary by location, is available at www.ihg.com/protectingourguests. The site also contains more information on steps guests may take.

It is always advisable to remain vigilant to the possibility of fraud by reviewing your payment card statements for any unauthorized activity. You should immediately report any unauthorized charges to your card issuer because payment card rules generally provide that cardholders are not responsible for unauthorized charges reported in a timely manner. The phone number to call is usually on the back of your payment card.

On behalf of franchisees, IHG has been working closely with the payment card networks as well as with the cyber security firm to confirm that the malware has been eradicated and evaluate ways for franchisees to enhance security measures. Law enforcement has also been notified. IHG also has established a dedicated call center to answer any questions affected guests may have.

For additional information about this incident, please visit the IHG website at www.ihg.com/protectingourguests.

About IHG

IHG® (InterContinental Hotels Group) [LON:IHG, NYSE:IHG (ADRs)] is a global organisation with a broad portfolio of hotel brands, including InterContinental® Hotels & Resorts, Kimpton® Hotels & Restaurants, HUALUXE® Hotels and Resorts, Crowne Plaza® Hotels & Resorts, Hotel Indigo®, EVEN® Hotels, Holiday Inn® Hotels & Resorts, Holiday Inn Express®, Staybridge Suites® and Candlewood Suites®. IHG franchises, leases, manages or owns nearly 5,100 hotels and more than 750,000 guest rooms in almost 100 countries, with nearly 1,500 hotels in its development pipeline. IHG also manages IHG® Rewards Club, the world's first and largest hotel loyalty programme, with nearly 99 million members worldwide. InterContinental Hotels Group PLC is the Group's holding company and is incorporated in Great Britain and registered in England and Wales. More than 350,000 people work across IHG's hotels and corporate offices globally. Visit www.ihg.com for hotel information and reservations and www.ihgrewardsclub.com for more on IHG Rewards Club. For our latest news, visit: www.ihg.com/media.ihg, payment card, cyber security, secure payment solutions

Contact:
Neil Hirsch
neil.hirsch@ihg.com

Coming Up In The June Online Hotel Business Review




{300x250.media}
Feature Focus
Sales & Marketing: Who Owns the Guest?
Hotels and OTAs are, by necessity, joined at the hip and locked in a symbiotic relationship that is uneasy at best. Hotels require the marketing presence that OTAs offer and of course, OTAs guest’s email when it sends guest information to a hotel, effectively allowing OTAs to maintain “ownership” of the guest. Without ready access to guest need hotel product to offer their online customers. But recently, several OTAs have decided to no longer share a data, hotels are severely constrained from marketing directly to a guest which allows them to capture repeat business – the lowest cost and highest value travelers. Hotels also require this data to effectively market to previous guests, so ownership of this data will be a significant factor as hotels and OTAs move forward. Another issue is the increasing shift to mobile travel bookings. Mobile will account for more than half of all online travel bookings next year, and 78.6% of them will use their smartphone to make those reservations. As a result, hotels must have a robust mobile marketing plan in place, which means responsive design, one-click booking, and location technology. Another important mobile marketing element is a “Click-to-Call” feature. According to a recent Google survey, 68% of hotel guests report that it is extremely/very important to be able to call a hotel during the purchase phase, and 58% are very likely to call a hotel if the capability is available in a smartphone search. The June Hotel Business Review will report on some of these issues and strategies, and examine how some sales and marketing professionals are integrating them into their operations.