2014–2015 Hilton — POS malware; cardholder track data at restaurants/some hotel PoS
Data compromised
Mag-stripe–equivalent card data elements; no consolidated public victim tally
Technical writeup
Hilton Worldwide confirmed payment-card–scraping malware on some point-of-sale systems, exposing cardholder name, PAN, expiration, and CVV for guests who swiped cards during two windows—late 2014 and spring–summer 2015—while stressing that addresses and PINs were not in scope. The disclosure rode the mid-2010s wave of hospitality POS intrusions alongside peer chains and triggered complimentary credit monitoring messaging in Hilton’s public statement.
Root cause
Point-of-sale malware on subset of food-and-beverage or property payment lanes