In recent years, the accelerated growth of digitization and the adoption of new technologies have profoundly transformed the way we work, communicate and store information. However, this same environment has been exploited by cybercriminals, who have become increasingly sophisticated and aggressive in their attack methods.
No sector is spared and companies operating in the tourism sector are among the preferred targets. Tourism, a sector already hard hit in this uncertain period, is at risk of being hit by other viruses: its main players have some weaknesses in terms of cybersecurity and the hackers are aware of this. In the case of French tourism alone, losses are currently estimated at between 30K and 40K million.
Level of cybersecurity in the travel industry: An alarming finding
An analysis carried out by the IT security specialist Proofpoint on nearly 300 airlines around the world has produced a most worrying conclusion: only 7% of the companies are adequately protected!
The study was carried out on the basis of the DMARC protocol (Domain-based Message Authentication, Reporting and Conformance) and consisted mainly in assessing the level of security of a company’s messaging system.
In fact, email spoofing is one of the favorite areas for cybercriminals to entrap airline customers. More specifically, hackers impersonate companies, most often using their domain names, and generally resort to phishing to lure customers.
The DMARC protocol uses the DKIM and SPF standards to authenticate the identity of message senders. Of the companies surveyed, 39% still have a DMARC record but are not fully protected, as they have not subscribed to all the protection.
North Asia and China have the worst results: no company complies with the protocol. There are no domain names registered, so vulnerability is very high. In Europe, the figures remain at the world average.
Investing in cybersecurity: a vital issue for the travel industry
The tourism sector continues to lag behind in terms of cybersecurity. Despite the evolving environment, many companies, both large and small, still lack the information and measures necessary to adequately protect themselves in the digital realm.
Often, data security is left behind as managers, still facing ongoing challenges in an increasingly complex environment, do not prioritize cyber protection as one of their top concerns.
Three major players in the industry have recently been the target of attacks with serious consequences: EasyJet, the cruise line Carnival and the travel retailer MisterFly.
In the first, hackers hijacked customers’ banking data, while the other two fell victim to ransomware over the summer. However, attacks, particularly ransomware, are nothing new in the travel industry.
The general silence of the victims of cyber-attacks, as well as the lack of information sharing between sister companies, does not help to improve the situation. If this situation is not reversed, the tourism sector will be a paradise for cybercriminals in a few years’ time.
There are no thirty-six solutions: all companies in the sector must invest in cybersecurity and update themselves regularly. According to ALSID, another expert in the field, we are only at the beginning of a major wave of attacks.
To summarize, companies in the tourism sector are vulnerable and, counter-intuitively, they are even more so because their activities have been suspended for health reasons. The measures taken, such as teleworking and the limitation of budgets, especially those related to cybersecurity, as well as the many uncertainties currently facing the sector, paint a rather bleak picture…
For more details, you can contact us at Info@bravent.net



