2017 Sabre Hospitality (SynXis CRS) — payment card & reservation data exposure (Aug 2016–Mar 2017)
Data compromised
Payment card data and hotel reservation attributes for affected bookings
Technical writeup
Sabre Hospitality Solutions disclosed unauthorized access to its SynXis Central Reservations environment in which attackers could access unencrypted payment-card data (number, expiration, card security code) and certain reservation details for a bounded window from August 10, 2016 through March 9, 2017. Public multistate regulatory summaries cited roughly 1.3 million payment cards affected. Sabre stated categories such as SSN/passport were not involved in the same hotel-CRS scope.
Root cause
Long-running unauthorized access within hospitality central-reservations infrastructure