← Hilton Worldwide Holdings

2014–2015 Hilton — POS malware; cardholder track data at restaurants/some hotel PoS

2015 Unknown records affected Share on X

Data compromised

Mag-stripe–equivalent card data elements; no consolidated public victim tally

Technical writeup

Hilton Worldwide confirmed payment-card–scraping malware on some point-of-sale systems, exposing cardholder name, PAN, expiration, and CVV for guests who swiped cards during two windows—late 2014 and spring–summer 2015—while stressing that addresses and PINs were not in scope. The disclosure rode the mid-2010s wave of hospitality POS intrusions alongside peer chains and triggered complimentary credit monitoring messaging in Hilton’s public statement.

Root cause

Point-of-sale malware on subset of food-and-beverage or property payment lanes

References