Choice Hotels confirmed Radisson guest records taken in MOVEit attacks

Organization
Choice Hotels International
Exploit
Supply Chain Attack
Industry
Hospitality

Choice Hotels International confirmed in July 2023 that guest records held by its Radisson Hotels Americas business had been accessed by attackers exploiting a vulnerability in Progress Software's MOVEit Transfer file transfer product.

A company spokesperson said Choice had "identified a limited number of guest records that were accessed by these bad actors" and that it was in the process of notifying the affected guests. The company declined to say how many people were involved or which categories of data had been taken.

Radisson Hotels Americas, which Choice acquired in 2022, appeared on the leak site run by the Clop ransomware group during the week of July 11, 2023. Clop was behind the mass exploitation of the MOVEit flaw, tracked as CVE-2023-34362, which began at the end of May 2023 and eventually drew in hundreds of organizations across banking, insurance, healthcare, education and government. TechCrunch reported that by mid-July the group had claimed close to 270 victim organizations, together accounting for more than 17 million individuals.

The disclosure came alongside a wave of other MOVEit notifications. Radisson Hotels Americas comprised nearly 600 hotels in the United States, Canada, Latin America and the Caribbean. As of the reporting date Choice Hotels had not published a total for affected guests or a list of the data types involved, and its investigation was continuing.

Sources