About 300 Hyatt hotels in 54 countries had their payment card systems infected with malware in breach announced last year
250 Hyatt hotels infected last year with payment data stealing malware — The hotel chain has admitted that 250 hotels in 54 countries were affected by the data breach.
Context & Ripple Effects
Hyatt first disclosed the incident in late December, notifying customers that malware had been found on its payment processing systems; this update puts a number and a map on that notice — roughly 300 hotels across 54 countries with infected point-of-sale systems. The disclosure lands weeks after Hilton Worldwide identified and eradicated POS malware that collected credit card data from late 2014 to mid-2015, making large global hotel chains the recurring target of the same attack pattern.
First-order effects
- Customers who paid at affected Hyatt properties face exposed card data and potential reissuance through their banks, while Hyatt bears investigation, remediation, and notification costs across its franchise network.
Second-order effects
- With Hilton hit on essentially the same vector just weeks earlier, other global hotel operators face pressure to audit and harden their own point-of-sale systems before they become the next disclosed name.
Third-order effects
- A run of chain-wide POS breaches points hospitality toward centralized payment security — tokenization and updated terminal standards at franchised properties — as card networks and regulators weigh whether brand-level disclosure is enough.
The trend: Payment-card malware is sweeping through global hotel chains' point-of-sale systems one major brand at a time, forcing the hospitality industry toward standardized payment security.