Taj Hotels investigates claimed leak of data on 1.5 million guests

Organization
Indian Hotels Company Limited (Taj Hotels)
Exploit
Hacking
Industry
Hospitality

In November 2023 a threat actor using the handle Dnacookies advertised a dataset said to contain the personal details of about 1.5 million guests of Taj Hotels, the hospitality chain operated by Indian Hotels Company Limited, part of the Tata group.

The seller said the records covered the period from 2014 to 2020 and had not been circulated before, and released a sample of roughly 1,000 unique rows. According to The Cyber Express, the advertised fields included names, addresses, mobile numbers and membership identification numbers. The asking price for the full dataset was 5,000 US dollars, and the seller attached conditions to any sale: negotiations only through an intermediary with administrative privileges, no splitting of the data, and no further samples.

Indian Hotels Company Limited said it had been made aware of someone claiming possession of a limited customer dataset that it characterized as non-sensitive. The company said it had notified the relevant authorities, including India's Computer Emergency Response Team, and that there was no indication of a current or ongoing security issue or any impact on business operations. It did not confirm the figure of 1.5 million, which originated with the seller rather than the company.

Contemporary reporting did not establish how the data had been obtained, and the authenticity of the wider dataset beyond the published sample was not independently verified. The company said it would continue to monitor its systems while the claim was investigated.

Sources