Weakest link in cybersecurity. Poles’ rail revolution. 24/7 concierge. FlyAkeed gets boost.
22/09/2023 by Ian Jarrett

Humans are the weakest link in cybersecurity

The vulnerability of the travel industry to modern tech has been exposed by the cyberattack on MGM Resorts in Las Vegas which crippled the company’s operations.

Frustrated guests were unable to check in at MGM Resorts, electronic payments were disrupted and digital key cards, slot machines, ATMs and paid parking systems were all compromised by the attacks.

As of 21 September, MGM’s online booking system was still offline.

Caesars Entertainment also suffered a cyberattack this month but not to the same extent as MGM.

The Wall Street Journal reported that Caesars paid a US$15 million ransom to regain control of its operations, although it is unclear whether MGM Resorts has also paid the perpetrators of the attack on its systems.

“It’s bonkers,” Alex Waintraub, a cyber crisis management expert, told Forbes. “Companies are spending sometimes hundreds of millions of dollars on preventative care, detection care, protection care, endpoint detection response, and so on.

“And guess what? The simplest, unsophisticated ways are how the threat actors are getting in: Click on this link and type in your credentials.”

Cybersecurity experts say they have identified a consistent pattern of attacks where hackers impersonated a victim firm’s employees and convinced their information technology helpdesk into providing them duplicate access.

ALPHV, also known as Black Cat, claimed responsibility for attacking MGM while an affiliated group that calls itself Scattered Spider hit Caesars.

When Scattered Spider breaks into a company, it installs the encrypting programme that belongs to BlackCat, experts say.  BlackCat then handles the ransom negotiations and the two groups split the proceeds.

ALPHV claimed that it took 10 minutes to infiltrate MGM’s system after identifying an MGM tech employee on LinkedIn and then calling the company’s support desk. Scattered Spider gained entry to Caesars’ system by deceiving an employee at a third-party vendor.

“The continued success of social engineering as a tactic demonstrates that humans are often the weakest link in the chain,” said Alex Hamerstone, advisory solutions director at cybersecurity firm, TrustSec.

Hacking of travel-related computer systems is becoming more prevalent, the Daily Telegraph noted.  A Threat Intelligence Report by Check Point Research found that the global average number of attacks against organisations in the tourism and leisure sector increased by 60% from Jan-June 2022, compared to the first half of 2021.

And in figures released by the Australian Travel Industry Association, the 2022 Cost of a Data Breach Report found that the average cost of a data breach for Australian companies is US$2.92 million.

Travel companies have been frequent targets for spammers. Bitdefender’s antispam and antimalware filters last year flagged a malicious campaign where the spammers impersonated popular international hotel chains and tour operators to deliver credential‐stealing trojans. Names of impersonated brands include Accor Hotels, Panorama Tours, Meritus Hotels and others,” according to Bitdefender.

Marriott, Starwood and IHG have also reported data breaches at various times.

But it’s not just hotels and resorts who are having challenges with technology. Last month, the UK suffered a huge air traffic control failure, resulting in more than 2,000 flights being cancelled.  Authorities blamed the meltdown on incorrect data being entered into the ATC systems,  indicating it was not a cyberattack.

ONE LAST WARNING:  A recent report by Atlas VPN reveals that Mondays are particularly risky for cyberattacks, as 27% of phishing emails targeting C-Suite employees are sent on the first day of the workweek.

 

The concierge that works while you prune the roses

Travel tech company eviivo has launched eviivo Concierge, a Generative AI-powered guest messaging tool for property owners, which the company says is the first global property management platform to fully integrate the power of AI as a time-saving guest management feature.

The Eviivo Concierge virtual assistant available on customers’ websites leverages the property’s accommodations service data to predictively answer guest questions based on any commands or directives, provide personalised assistance and recommendations, “while saving property owners valuable time and money, increasing efficiency and driving more bookings”.

Usama Ahmed, eviivo product director, says, “Our award-winning mobile app allows hosts to run their business anywhere, anytime, right in the palm of their hand — and now with eviivo’s 24/7 digital Concierge, property owners can have dozens of guest questions answered while they tend to their garden, vacation with family or even while they sleep.”

 

Poles on track with rail innovation

Polish start-up Nevomo has developed a technology that can adapt traditional railroads to support electrified, high-speed travel while still accommodating traditional trains.

Nevomo successfully tested its MagRail system over a series of several months this year along a 0.45-mile track in Nowa Sarzyna, Poland.

MagRail uses magnetic levitation — similar to hyperloop systems, except without the vacuum-sealed tubes — to propel train cars forward without the friction of conventional rail.

Nevomo has entered memorandums of understanding with France’s SNCF national railway company and the Italian state railway infrastructure management company Rete Ferroviaria Italiana to evaluate capacity and efficiency benefits of MagRail and assess the system’s economic and technical feasibility.

Source: Travel Weekly USA

 

Saudi start-up scores funds for growth

Saudi Arabian travel technology start-up FlyAkeed has secured a substantial $15.2 million investment to propel its growth strategy.

FlyAkeed offers conventional browsing and booking options across major international airlines’ booking platform for both B2C and B2B customers.

It allows travel managers to gain real-time insights into the ticketing process, while the inclusion of a corporate cash wallet feature empowers businesses to oversee their booking activities, streamlining their travel management.

BACK