CSIDB logo
Incident

Brunswick Hotel & Tavern

Incident posture

Attack window
Nov 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-17 09:23

Linked entities

Victim
Brunswick Hotel & Tavern
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Olympia Hotel Management discovered malware on a front desk computer at the Brunswick Hotel & Tavern, potentially compromising guest names and payment card data over an eight-month period. The sophisticated malware evaded antivirus detection and may have enabled remote access to card information, though no conclusive evidence confirmed data exfiltration. Approximately 2,600 guests were impacted, with the hotel taking steps to remove the malware, enhance system security, notify affected individuals, and offer complimentary credit monitoring services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Malware was discovered on a front desk computer system at the Brunswick Hotel & Tavern, a Maine-based property managed by Olympia Hotel Management, on August 12, 2015. Security consultants investigating the incident determined the malware may have been active on the system between November 29, 2014, and July 21, 2015. The malicious software was designed to capture names and payment card information from guests during transactions while evading detection by standard anti-virus programs. Investigators characterized the malware as sophisticated due to its ability to avoid security measures and permit potential remote access to the harvested data. No conclusive evidence was found to confirm whether attackers successfully exfiltrated the payment card data or personally identifiable information from the compromised system. The hotel began notifying an undisclosed number of potentially affected guests on August 25, 2015, through individual letters that described the nature of the security incident.

Olympia Hotel Management implemented measures to eliminate the malware infection and enhance the security of the hotel's computer systems following the discovery. The company offered complimentary credit monitoring services to all individuals whose information may have been exposed during the eight-month period of potential vulnerability. Updated reports indicated approximately 2,600 guests were impacted by the data security incident at the Brunswick Hotel & Tavern. The notification letters emphasized that while payment card details and names were at risk, investigators could not confirm actual unauthorized access or misuse of the information. The hotel management worked with cybersecurity consultants to address the breach and prevent similar incidents through improved system safeguards and monitoring protocols.

Sources

Sources available to members: 1 source.

CSIDB