Cyberattacks surge, how to stay safe virtually when travelling in the real world
12/10/2022 by Arvindh Yuvaraj

DATA breaches, cyberattacks, information theft – none of these are shocking headlines in 2022. Yet, while cybercrime has become a byproduct of our evolving online world, it doesn’t make these acts any less dangerous. In fact, an upcoming report by Phocuswright titled “Cybersecurity in travel goes beyond technology” outlines how cybercriminals are using innovative ways to attack travel companies worldwide.

According to the forthcoming report, travel and leisure is one of the most impacted industries globally, with digital fraud attempts rising 155.9% in the last year, mainly targeting credit cards, personal identifiable information (PII), reward programs and publicly available internet. It’s interesting to note that future vulnerabilities include artificial intelligence and the metaverse.

Just last month, we learned that Optus, a major telecoms service provider in Australia, was hit by a data breach that exposed the personal details of 10 million customers. The details included identity document numbers such as passport, license and Medicare numbers for hundreds of thousands of Australians. More recently, Singtel (Optus’ parent company) confirmed that it was also compromised in a cyberattack two years ago, exposing the personal data of 129,000 customers and 23 businesses.

Why is this important information for travellers?

Well, think about the first thing you buy in another country if you’re not on an International Roaming plan – a local sim card. They’re easy to find, affordable… and require a chunk of your personal data to be activated. Data touchpoints like these are a dime a dozen when travelling overseas – when checking-in at the hotel, when applying for local travel passes, and when signing up for local services.

“The travel industry functions in an environment where numerous potential points of failure make the prevention and detection of cybersecurity breaches significantly more difficult relative to other industries,” says Robert Cole, senior research analyst, lodging and leisure travel at Phocuswright.

According to Darren Williams, CEO of cybersecurity company BlackFog, small hotel chains without adequate infrastructure are prime candidates as they are less likely to have invested in tools, processes and people to protect the organisation. Even fewer will have anti-data-exfiltration technology.

It’s quite clear that primary tactics used by cybercriminals aren’t new, they’re just evolving. Ransomware, where the aim is to get companies to pay to have their data unencrypted, still seems to be a prime method of extracting information. August saw the highest number of ransomware attacks so far this year, and September was shaping up to be just as high.

Another common tactic is phishing, where attackers send a “social engineering e-mail” that tricks people into clicking on links and providing information such as passwords. Chris Clements, vice president of solutions architecture at Cerberus Sentinel says that multifactor authentication can help prevent breaches, but it’s not foolproof, with text messages being the easiest to bypass.

So, what can we do as eager travellers ready to explore a world that has reopened (most of) its borders?

To better understand the nuanced nature of cybersecurity in the travel space, we got in touch with CF Fong, CEO and Cybersecurity Consultant, LGMS, to find out how to stay safe when on holiday / workcation / business trips:

Q: Why is the travel space a prime target for cyber-threats?

CF: The travel space requires a lot of personal identifiable information (PII) that is valuable for hackers and criminals. They can leverage PII for scams and other crimes. The moment you check-in at the hotel, you need to provide your personal information and credit card details. Some hotels provide (subscription-based) Wi-Fi services, and you’ll need your credit card for that as well.

Q: What can travelers do to ensure their data is protected when overseas and traveling?

CF: Basically, apply common sense. Do not give out personal information to strangers. Key in your credit card PIN discreetly. When connecting to public Wi-Fi, always use VPN. And avoid conducting sensitive transactions over public Wi-Fi networks.

Q: How many people have proper internet security apps on their phones, though? Let alone VPN…

CF: True, I think the maturity or security awareness isn’t there yet. A lot of people still don’t understand the risks of public Wi-Fi. We wouldn’t know the level of security that’s implemented on the network. Those of us who have been in the industry for a long time know how easy it is to set up a fake access point – within minutes. Let’s say you’re sitting in a Statbucks to use their Wi-Fi – I can bring a laptop, sit close to you, and start a new access point named “Starbucks”, connect your computer to mine, and then capture your internet activities. It’s that simple. And from a technical point of view, the end-user will have no idea what has happened behind the scenes.

Q: So the best way is to ask the hotel, or in this case the Starbucks employee, what their legitimate Wi-Fi network is?

CF: I mean the hackers could also set up a Wi-Fi network that bears the same name as the legitimate Wi-Fi. That’s why the best practice is to use VPN. Even if you accidentally connect to a network set up by hackers, VPN adds layers of security to prevent hackers from spying on what you’re doing online.

Q: Is there any way to find out if our data has been compromised? Like in the Optus / Singtel data breach?

CF: Sometimes it’s beyond our control and the responsibilities are with third parties like the telcos. You can reach out to your service provider but whether they’ll disclose that information is another question. Sooner or later, the data that was presumably stolen will be put on sale by the hackers. Security companies can then trace that data. But for ordinary users, contact your service provider to know the extent of the data leak.

Q: Are there any new tactics in this space that aren’t being highlighted yet?

CF: Phishing is still mainstream – and because of the massive amounts of data leaks, phishing has become more convincing. For the future – in the next 3 to 5 years, we expect to see more IoT devices coming into our lives, like smart home appliances, smart wearable devices, even autonomous cars… so the next phase of hacking will most likely revolve around Internet of Things.

Q: Are cybersecurity companies getting better at thwarting these attacks? I’m looking for some good news here, CF!

CF: Yes, cybersecurity companies are catching up, but the end-users are not. And this has always been the issue. We have so many types of protection and so many controls to be secure – but ordinary users are usually not bothered until they’ve been hit. Unfortunately, many people don’t yet have a proactive mindset when it comes to cybersecurity.

 

“Yes, cybersecurity companies are catching up, but the end-users are not. And this has always been the issue.” – CF Fong, Cybersecurity Consultant

 

The Phocuswright report, due to be released this month, also adds these security measures to the list:

  • Hotels and airlines providing Wi-Fi services need to be aware of individuals capable of spoofing internet access points with network IDs that are similar to the real ones.
  • Hotels allowing room charges from dining outlets and recreational facilities often only require a name and room number for validation. If the guest’s name and room number are overheard at the front desk, or a lost key packet with the name/room number is found, erroneous services may be charged to the victim’s room and not be discovered until the day of departure.

All of this to say, keep travelling!

The purpose of this article (and the report that inspired it) isn’t to frighten or to illustrate a bleak environment, but to encourage safe travels as the line between virtual and physical continues to blur. Take the necessary steps to keep your digital data secure as far as possible, just as you would a physical document like a passport.

BACK