US spy agency asked hacker to steal foreign diplomats data journalists claim
A hacker linked to unspecified US spy agencies reportedly attacked hotel reservation site Booking.com in 2016, targeting foreign diplomats and other individuals in the Middle East. The company did not notify customers of the hack.
The alleged perpetrator, dubbed âAndrew,â stole the âdetails of thousands of hotel reservationsâ across Middle Eastern countries, according to a report published on Wednesday by Dutch newspaper NRC Handelsblad. The bombshell article was citing accusations made in a new book by its journalists.
An employee at the joint US-Dutch firmâs Amsterdam headquarters discovered the hack by accident after coming across an unauthorized access via a poorly secured server. The breach gave Andrew and their associates access to customer data, travel plans, and unique user personal ID numbers (PINs).
Read more
The hack was verified by three former security specialists and a manager at the company at the time of the breach. Enlisting US private investigators, Booking.comâs security team determined two months later that Andrew worked for a company that carried out assignments from US intelligence services. The actual agency involved in the incident was not identified.
Although Booking.com alerted the Dutch intelligence agency AIVD, it apparently did not notify users or the Dutch Data Protection Authority (AP) â" later justifying this decision on the grounds that it was not legally required to do so at the time. The hack predated the implementation of the EUâs General Data Protection Regulation (GDPR), which requires data leaks to be disclosed to state authorities.
However, unnamed sources revealed that the companyâs IT specialists were uncomfortable with the managementâs decision â" based on advice from London-based law firm Hogan Lovells â" to keep the breach under wraps. Under the applicable privacy laws of the time, the company was still required to inform affected persons when the data theft âwould likely have adverse effects on the private lives of individuals.â
Read more
Claiming that âno sensitive or financial informationâ was accessed in the leak, the company said in a statement that its âleadership at the time worked to follow the principles of the Dutch Data Protection Act.â Under that law, companies were advised to issue a notification âonly if there were actual adverse negative effects on the private lives of individuals, for which no evidence was detected.â
The report comes almost exactly eight years after NSA whistleblower Edward Snowden revealed the existence of a special program called âRoyal Conciergeâ run by British spy agency GCHQ that conducted surveillance on more than 350 hotels hosting foreign diplomats and officials.
While the Snowden documents did not identify any specific reservation websites, a former Booking.com security specialist told the Dutch paper that it would be âcrazy if [it] werenât on that list.â
If you like this story, share it with a friend!