Company Details
holiday-inn-hotels
12,023
42,608
7211
holidayinn.com
0
HOL_2975596
In-progress

Holiday Inn Company CyberSecurity Posture
holidayinn.comMore than an iconic place to stay, Holiday Inn Hotels are a place to be in the moment–gathered to celebrate with family, laughing with friends, sharing a meal with the team, or just for some well-deserved me-time. No matter the reason you travel, when you’re here, you’re right where you’re meant to be. Book with us and become an IHG One Rewards member.
Company Details
holiday-inn-hotels
12,023
42,608
7211
holidayinn.com
0
HOL_2975596
In-progress
Between 750 and 799

Holiday Inn Global Score (TPRM)XXXX

Description: On February 3, 2017, the California Office of the Attorney General reported that Six Continents Hotels, Inc. (doing business as InterContinental Hotels Group - IHG) experienced a data breach affecting guests' payment card data at 12 properties. The breach involved malware installed on servers processing payment cards used at restaurants and bars from August 1, 2016, to December 20, 2016, but left front-desk card transactions unaffected; specific numbers of affected individuals are currently unknown.
Description: The California Office of the Attorney General reported a data breach involving InterContinental Hotels Group on April 14, 2017. The breach occurred between September 29, 2016, and December 29, 2016, due to malware accessing payment card data at certain franchise locations in the Americas. The number of affected individuals is currently unknown, and specific types of information compromised might include cardholder names, card numbers, expiration dates, and security codes.
Description: InterContinental Hotels Group PLC was targeted in a cyberattack that knocked its booking systems offline. An unauthorized activity created technical issues and resulted in its booking channels and other applications being significantly disrupted. IHG immediately implemented response plans, notified regulatory authorities and engaged external specialists to investigate the incident.
Description: Thieves gained access to the payment card systems of over 1,000 hotels owned by the InterContinental Hotels Group. The InterContinental San Francisco, Holiday Inn Resort – Aruba, and InterContinental Chicago Magnificent Mile are among the properties that are impacted. The inquiry found evidence of malware activity between September 29, 2016, and December 29, 2016, that was intended to obtain payment card information from cards used on-site at front desks at specific IHG-branded franchise hotel sites. The business emphasised that although some payment systems have been infiltrated by malware, there is no proof that credit card data was accessed thereafter.


No incidents recorded for Holiday Inn in 2025.
No incidents recorded for Holiday Inn in 2025.
No incidents recorded for Holiday Inn in 2025.
Holiday Inn cyber incidents detection timeline including parent company and subsidiaries

More than an iconic place to stay, Holiday Inn Hotels are a place to be in the moment–gathered to celebrate with family, laughing with friends, sharing a meal with the team, or just for some well-deserved me-time. No matter the reason you travel, when you’re here, you’re right where you’re meant to be. Book with us and become an IHG One Rewards member.

We are Accor We are more than 290,000 hospitality experts placing people at the heart of what we do, creating emotion for our guests, and nurturing passion for service and achievement beyond limits. Building on the strength of our teams and of our fully integrated ecosystem of leading brands, perso

Mandarin Oriental Hotel Group is the award-winning owner and operator of some of the world’s most luxurious hotels, resorts and residences. Having grown from its Asian roots into a global brand, the Group now operates 43 hotels, 12 residences and 23 exclusive homes in 26 countries and territories, w

We’re adventure seekers. Smile givers. Impact makers. We believe in the power of travel. It broadens horizons for our customers, and for our people too. New places to live, new roles to explore, new communities to join. It’s yours for the taking. We’re TUI, a leading global travel and leisure exp

An IHG hotel. IHG Hotels & Resorts [LON:IHG, NYSE:IHG (ADRs)] is a global hospitality company, with a purpose to provide True Hospitality for Good. At Holiday Inn Express, we strive to make every interaction you have with us simple, smart and refreshingly engaging. With over 3,000 hotels in 75 di

Kerzner International has built a diverse collection of iconic brands and luxury properties, earning international acclaim for pioneering destination-defining hospitality, delivering unrivalled service, and curating transformative guest experiences. We are renowned for creating hospitality brands

Minor Hotels is a global hospitality leader with over 560 hotels and resorts across six continents, a diverse portfolio of F&B businesses and a selection of luxury transportation services. With over four decades of experience, we build stronger brands, foster lasting partnerships, and drive business
Hilton Grand Vacations is a global leader in vacation ownership, developing, marketing and operating a portfolio of high-quality, shared-ownership properties in highly desired vacation destinations. Our company also manages and operates innovative club membership programs providing exclusive exchang

Caesars Entertainment, Inc. is the largest casino-entertainment Company in the U.S. and one of the world's most diversified casino-entertainment providers. Since its beginning in Reno, NV, in 1937, Caesars Entertainment, Inc. has grown through development of new resorts, expansions and acquisitions.

Delaware North is a global leader in the hospitality and entertainment industry. The company annually serves more than a half-billion guests across three continents, including at high-profile sports venues, airports, national and state parks, restaurants, resorts, hotels and casinos. Building on mor
.png)
Learn the basics behind keeping your personal and financial data safe online in this hands-on class using library laptops. Registration required.
Tuesday, June 24, 2025 7:11PM IST (1:41PM GMT). Mumbai, Maharashtra, India -- The 2nd Edition of the CyberSec Innovation Summit & Awards 2025,...
Anupam will lead global cybersecurity, compliance, and risk management initiatives to reinforce the trust and resilience of Biz2X platform.
Five Tattva Cyberhub Security (5Tattva) has acquired a major stake in Zeroday Ops, a cybersecurity firm known for its advanced threat...
RAH Infotech, a distributor and provider of cybersecurity and IT solutions, announced the appointment of Jitendra Khadke as Senior Vice...
Hotel, motel, Holiday Inn—if AI starts acting up, then you call IT in. As the hospitality industry integrates automation and generative AI...
Inspira Enterprise, a global cybersecurity services organization announced the appointment of Rajesh Ananthakrishnan as President and Head...
Most recently, Zafrir was the co-founder and managing partner at Team8, a company-building venture group focused on cyber security,...
Exabeam, a global cybersecurity leader that delivers AI-driven security operations, today announced the appointment of Mike Byron as Chief Financial Officer (...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Holiday Inn is http://www.holidayinn.com/.
According to Rankiteo, Holiday Inn’s AI-generated cybersecurity score is 790, reflecting their Fair security posture.
According to Rankiteo, Holiday Inn currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Holiday Inn is not certified under SOC 2 Type 1.
According to Rankiteo, Holiday Inn does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Holiday Inn is not listed as GDPR compliant.
According to Rankiteo, Holiday Inn does not currently maintain PCI DSS compliance.
According to Rankiteo, Holiday Inn is not compliant with HIPAA regulations.
According to Rankiteo,Holiday Inn is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Holiday Inn operates primarily in the Hospitality industry.
Holiday Inn employs approximately 12,023 people worldwide.
Holiday Inn presently has no subsidiaries across any sectors.
Holiday Inn’s official LinkedIn profile has approximately 42,608 followers.
Holiday Inn is classified under the NAICS code 7211, which corresponds to Traveler Accommodation.
No, Holiday Inn does not have a profile on Crunchbase.
Yes, Holiday Inn maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/holiday-inn-hotels.
As of November 28, 2025, Rankiteo reports that Holiday Inn has experienced 4 cybersecurity incidents.
Holiday Inn has an estimated 13,646 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach and Cyber Attack.
Title: Cyberattack on InterContinental Hotels Group PLC
Description: InterContinental Hotels Group PLC was targeted in a cyberattack that knocked its booking systems offline. An unauthorized activity created technical issues and resulted in its booking channels and other applications being significantly disrupted.
Type: Cyberattack
Title: Data Breach at InterContinental Hotels Group
Description: Thieves gained access to the payment card systems of over 1,000 hotels owned by the InterContinental Hotels Group. The breach affected properties including the InterContinental San Francisco, Holiday Inn Resort – Aruba, and InterContinental Chicago Magnificent Mile. The inquiry found evidence of malware activity between September 29, 2016, and December 29, 2016, that was intended to obtain payment card information from cards used on-site at front desks at specific IHG-branded franchise hotel sites. The business emphasised that although some payment systems have been infiltrated by malware, there is no proof that credit card data was accessed thereafter.
Date Detected: 2016-12-29
Type: Data Breach
Attack Vector: Malware
Threat Actor: Unknown
Motivation: Financial Gain
Title: InterContinental Hotels Group Data Breach
Description: A data breach affecting guests' payment card data at 12 properties of InterContinental Hotels Group (IHG). Malware was installed on servers processing payment cards used at restaurants and bars from August 1, 2016, to December 20, 2016, but front-desk card transactions were unaffected.
Date Detected: 2017-02-03
Date Publicly Disclosed: 2017-02-03
Type: Data Breach
Attack Vector: Malware
Title: Data Breach at Six Continents Hotels, Inc.
Description: The California Office of the Attorney General reported a data breach involving Six Continents Hotels, Inc. (d/b/a InterContinental Hotels Group) on April 14, 2017. The breach occurred between September 29, 2016, and December 29, 2016, due to malware accessing payment card data at certain franchise locations in the Americas. The number of affected individuals is currently unknown, and specific types of information compromised might include cardholder names, card numbers, expiration dates, and security codes.
Date Detected: 2017-04-14
Date Publicly Disclosed: 2017-04-14
Type: Data Breach
Attack Vector: Malware
Common Attack Types: The most common types of attacks the company has faced is Breach.

Systems Affected: booking systemsbooking channelsother applications
Operational Impact: Significant disruption

Data Compromised: Payment card information
Systems Affected: Payment card systems
Payment Information Risk: ['High']

Data Compromised: Payment card data
Systems Affected: Servers processing payment cards
Payment Information Risk: High

Data Compromised: Cardholder names, Card numbers, Expiration dates, Security codes
Payment Information Risk: True
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Payment Card Information, , Payment card data, Cardholder Names, Card Numbers, Expiration Dates, Security Codes and .

Entity Name: InterContinental Hotels Group PLC
Entity Type: Corporation
Industry: Hospitality

Entity Name: InterContinental Hotels Group
Entity Type: Corporation
Industry: Hospitality
Location: Global

Entity Name: InterContinental Hotels Group (IHG)
Entity Type: Hospitality
Industry: Hotel
Location: Multiple locations

Entity Name: Six Continents Hotels, Inc. (d/b/a InterContinental Hotels Group)
Entity Type: Hospitality
Industry: Hotel
Location: Americas

Incident Response Plan Activated: True

Type of Data Compromised: Payment card information
Sensitivity of Data: High

Type of Data Compromised: Payment card data
Sensitivity of Data: High

Type of Data Compromised: Cardholder names, Card numbers, Expiration dates, Security codes
Sensitivity of Data: High


Source: California Office of the Attorney General
Date Accessed: 2017-02-03

Source: California Office of the Attorney General
Date Accessed: 2017-04-14
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney GeneralDate Accessed: 2017-02-03, and Source: California Office of the Attorney GeneralDate Accessed: 2017-04-14.

Investigation Status: Investigation in progress
Last Attacking Group: The attacking group in the last incident was an Unknown.
Most Recent Incident Detected: The most recent incident detected was on 2016-12-29.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2017-04-14.
Most Significant Data Compromised: The most significant data compromised in an incident were Payment card information, , Payment card data, cardholder names, card numbers, expiration dates, security codes and .
Most Significant System Affected: The most significant system affected in an incident was booking systemsbooking channelsother applications and Payment card systems and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were security codes, Payment card data, card numbers, expiration dates, cardholder names and Payment card information.
Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Investigation in progress.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.