Menu
Browse

SuperINN

Primary URL Location Industry
www[.]superinn[.]com
Country United States of America
Hospitality & Leisure Icon
Hospitality & Leisure
Profile

SuperINN operates as a hospitality provider that offers lodging accommodations to guests. The organization maintains properties that serve travelers seeking short‑term stays. To support its operations, SuperINN relies on an online platform that handles reservations and stores guest information. This platform includes functions for uploading images, managing profiles, and processing payments. Through these services, the company aims to provide a seamless experience for its clientele.

The company’s headquarters is located in the United States of America. In September 2018, a security breach exposed data belonging to a large number of individuals. The incident affected over 43,000 people spread across the United States and 64 other countries. Among those impacted, nearly 2,900 were residents of California. The compromised data included encrypted credit card numbers, names, addresses, phone numbers, and email addresses of guests.

Attackers gained access by exploiting a vulnerability in the authenticated image upload feature of SuperINN’s web application. They subsequently used a SQL injection flaw to extract additional encrypted cardholder data. In response, the organization removed malicious scripts, hardened its file upload controls, and patched the SQL injection issue. SuperINN also rotated the encryption keys used to protect stored payment information. These actions were taken to restore security and prevent further unauthorized access to guest data.

Incidents
Linked incidents available to members
1 incident