Go Back  FlyerTalk Forums > Miles&Points > Hotels and Places to Stay > Hilton | Hilton Honors
Reload this Page >

Honors account information security data breach

Community
Wiki Posts
Search

Honors account information security data breach

Thread Tools
 
Search this Thread
 
Old Apr 4, 2011, 3:58 pm
  #16  
 
Join Date: Jul 2003
Location: Salish Sea
Programs: DL,AC,HH,PC
Posts: 8,974
Originally Posted by KoKoBuddy
It's stuff like this why I never allow my credit card info to be stored on Hilton's (or any vendor's) website.
The compromised data shouldn't include CC information. Epsilon is a mass-mailer service, they'll have email addresses and probably names (first only ?) so the worst that's likely to happen is you get a phishing or infected e-mail.

I hope Epsilon doesn't even have the capability of storing more data even if its clients are dumb enough to send it.

Incidentally, ever notice the HHonors log-in page is not SSL ?
Wally Bird is offline  
Old Apr 4, 2011, 5:00 pm
  #17  
 
Join Date: Oct 2010
Posts: 948
Anyone else surprised that there was nothing resembling an apology in this email?

Maybe it's for legal reasons, but it's weak. Yes, it's not Hilton's fault directly, it's just the company that they hired for this purpose...
adventureadam is offline  
Old Apr 4, 2011, 5:09 pm
  #18  
 
Join Date: May 2009
Location: MSP
Programs: Promus Preferred, ITT Sheraton Club
Posts: 674
No bonus points?
Minneapolis is offline  
Old Apr 4, 2011, 5:21 pm
  #19  
In Memoriam
 
Join Date: Feb 2000
Location: Easton, CT, USA
Programs: ua prem exec, Former hilton diamond
Posts: 31,801
Originally Posted by Wally Bird
The compromised data shouldn't include CC information. Epsilon is a mass-mailer service, they'll have email addresses and probably names (first only ?) so the worst that's likely to happen is you get a phishing or infected e-mail.

I hope Epsilon doesn't even have the capability of storing more data even if its clients are dumb enough to send it.
That's pretty funny. It is about as far from the reality of the relation between Epsilon and Hilton as one could possibly get.

Epsilon has access to way more than the email and first name. Way more.
cordelli is offline  
Old Apr 4, 2011, 5:32 pm
  #20  
 
Join Date: May 2008
Location: YYZ
Programs: AC*SE, SPG Gold, HH D
Posts: 1,130
Originally Posted by cordelli
Epsilon has access to way more than the email and first name. Way more.
What information? Home address? Financial? Phone #s?
phedre is offline  
Old Apr 4, 2011, 6:07 pm
  #21  
 
Join Date: Jun 1999
Location: Somewhere
Posts: 1,230
Originally Posted by cordelli
That's pretty funny. It is about as far from the reality of the relation between Epsilon and Hilton as one could possibly get.

Epsilon has access to way more than the email and first name. Way more.
A few years ago they used to run the most of the HHonors site, not sure if that's still the case but if so they do have access to more than just email. I do think the letter was a weak apology and probably the result of a legal review.
sunil is offline  
Old Apr 4, 2011, 7:10 pm
  #22  
 
Join Date: Dec 2003
Location: St. Paul, MN
Programs: Walmart Super Elite
Posts: 727
Odd, because I received a notice from US Bank regarding this security breach but nothing from Hilton, and I've been a HH member long before I signed anything with US Bank.
Bago'peanuts is offline  
Old Apr 4, 2011, 7:23 pm
  #23  
Original Poster
 
Join Date: Oct 2003
Location: DCA
Programs: UA LT 1K, AA EXP, Bonvoy LT Titan, Avis PC, Hilton Gold
Posts: 9,658
Just got the same notice from Marriott.
cova is offline  
Old Apr 4, 2011, 7:33 pm
  #24  
FlyerTalk Evangelist
 
Join Date: Dec 2006
Location: Pacific Northwest
Programs: UA Gold 1MM, AS 75k, AA Plat, Bonvoyed Gold, Honors Dia, Hyatt Explorer, IHG Plat, ...
Posts: 16,850
Originally Posted by Wally Bird
The compromised data shouldn't include CC information. Epsilon is a mass-mailer service, they'll have email addresses and probably names (first only ?) so the worst that's likely to happen is you get a phishing or infected e-mail.
Right, but these phishing emails are potentially a bit more dangerous for the average person, because the hackers not only got names and email addresses, but also the knowledge that the person has a certain account with XYZ and uses that email address with that merchant/bank/... So instead of sending people a vague email trying to get them to provide confidential information, the phishing emails now can address them by name and mention that they have a credit card account with Chase or whatnot. Will quite likely increase the success rate somewhat.

I hope Epsilon doesn't even have the capability of storing more data even if its clients are dumb enough to send it.
Does Hilton use them to send out emails containing, say, account information (statements?) that might include hhonors numbers?

Incidentally, ever notice the HHonors log-in page is not SSL ?
No. When I visit it, it's

https://secure.hilton.com/en/hhonors/login/login.jhtml


Originally Posted by Bago'peanuts
Odd, because I received a notice from US Bank regarding this security breach but nothing from Hilton, and I've been a HH member long before I signed anything with US Bank.

Same here. US Bank was the first email on Friday. Since then I have received emails from Citi and Chase. No Hilton (yet).
notquiteaff is online now  
Old Apr 4, 2011, 7:39 pm
  #25  
 
Join Date: Jul 2003
Location: West Palm Beach FL USA
Posts: 385
now up to 5 emails with the same verbage

Goy Hilton then Marriott now Walgreens and 2 others all the same letter different mailling addys hummm
a1bengal is offline  
Old Apr 4, 2011, 7:45 pm
  #26  
 
Join Date: Jul 2001
Programs: Hilton Lifetime Diamond
Posts: 1,266
........and just got one from Target.......and TIVO
milesmilesmiles is offline  
Old Apr 4, 2011, 7:47 pm
  #27  
 
Join Date: Oct 2003
Location: YYZ
Posts: 1,629
This is a clear breach of their privacy policy, in particular:

Protecting Personal Information

Hilton will take appropriate measures to: (i) protect personal information collected against unauthorized access, disclosure, alteration or destruction,
Obviously appropriate measures were not taken or there never would have been the breach!
todd-r is offline  
Old Apr 4, 2011, 8:23 pm
  #28  
Moderator: CommunityBuzz!, OMNI, OMNI/PR, and OMNI/Games & FlyerTalk Evangelist
 
Join Date: Nov 2000
Location: ORD (MDW stinks)
Programs: UAMM, AAMM & ExPlat, Marriott lifetime Plat, IHG Plat, Hilton Diamond
Posts: 23,506
Originally Posted by todd-r
Obviously appropriate measures were not taken or there never would have been the breach!
I used to offer 'breach insurance' to my clients when I was with a previous employer. While a number of breaches were due to employee stupidity (left laptop in plain sight in car while running into Starbucks in the morning, or a flashdrive that wasn't cleared properly), there were a number that were caused by 'professional' hackers on companies that had numerous safeguards in place. Breaches will happen and continue to happen, how a company responds is what will set a company apart and maintain the customer's trust.
Sweet Willie is offline  
Old Apr 4, 2011, 8:41 pm
  #29  
sk3
Suspended
 
Join Date: Jan 2002
Location: LAX
Programs: AA Gold
Posts: 2,741
Originally Posted by Wally Bird
...Incidentally, ever notice the HHonors log-in page is not SSL ?
Originally Posted by notquiteaff
Interesting, in agreement with Wally Bird, I've noticed for sometime that logging in to Hilton is with an unsecured URL. I've had bookmarked HH's homepage and that's where I've always logged in:
http://hhonors1.hilton.com/en_US/hh/home_index.do

The page that notquiteaff linked I'd only see when I enter my account number incorrectly, and I would always just close out of that page. But I've now bookmarked notquiteaff's link and I'll be using that from now on.

FWIW the homepages for SPG.com and AA.com where I log in from are also NOT secured. notquiteaff - got a secure link for them?

Back on OT, I also received the email this afternoon but I'm not worried. If Epsilon was connected to my airline accounts I would be though - big time.

Sure my cc number is at Hilton, but I don't worry about that all. Being "robbed" by fraudulent cc usage is the one theft I wouldn't mind because I'm fully protected by the credit card's policy against fraud.

However, what I do worry about is ID Theft, having been a victim of it before. Someone had my name and SSN and was able to open a cell phone account which (not surprisingly) the thief never paid. They opened it under my name and SSN but with a different address so I never received any of the bills. It wasn't until it went to a collection agency who then tracked down my real address via my SSN that a notice was ever sent to me.

So the fact that airlines now have not only my name and address, but thanks to the Secure Flight policy, my DOB - if those accounts were breached ID thiefs would have a real leg up to wreak havoc with ones credit rating....
sk3 is offline  
Old Apr 4, 2011, 9:27 pm
  #30  
FlyerTalk Evangelist
 
Join Date: Dec 2006
Location: Pacific Northwest
Programs: UA Gold 1MM, AS 75k, AA Plat, Bonvoyed Gold, Honors Dia, Hyatt Explorer, IHG Plat, ...
Posts: 16,850
Originally Posted by sk3
Interesting, in agreement with Wally Bird, I've noticed for sometime that logging in to Hilton is with an unsecured URL. I've had bookmarked HH's homepage and that's where I've always logged in:
http://hhonors1.hilton.com/en_US/hh/home_index.do

The page that notquiteaff linked I'd only see when I enter my account number incorrectly, and I would always just close out of that page. But I've now bookmarked notquiteaff's link and I'll be using that from now on.

FWIW the homepages for SPG.com and AA.com where I log in from are also NOT secured. notquiteaff - got a secure link for them?
FWIW, I get the secured Hilton Honors login page if I go to http://hhonors.com and click on My Account in the upper right-hand corner.

Similar for SPG - the login screen on the home page itself may not be secured (I didn't check if it actually posts to an Https URL though), but if you click on the login link, you get

https://www.starwoodhotels.com/prefe...t%2Findex.html

AA is left as an exercise to the reader
notquiteaff is online now  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.