CSIDB logo
Organisation

SuperINN

Profile

Primary URL
www[.]superinn[.]com
Location
United States of America
Sector
Hospitality & Leisure
Known incidents
1 incident
Updated
2026-06-27 07:09
Aliases
1 alias

Organisation tracking is available to eligible accounts.

Profile narrative

SuperINN operates as a hospitality provider that offers lodging accommodations to guests. The organization maintains properties that serve travelers seeking short‑term stays. To support its operations, SuperINN relies on an online platform that handles reservations and stores guest information. This platform includes functions for uploading images, managing profiles, and processing payments. Through these services, the company aims to provide a seamless experience for its clientele.

The company’s headquarters is located in the United States of America. In September 2018, a security breach exposed data belonging to a large number of individuals. The incident affected over 43,000 people spread across the United States and 64 other countries. Among those impacted, nearly 2,900 were residents of California. The compromised data included encrypted credit card numbers, names, addresses, phone numbers, and email addresses of guests.

Attackers gained access by exploiting a vulnerability in the authenticated image upload feature of SuperINN’s web application. They subsequently used a SQL injection flaw to extract additional encrypted cardholder data. In response, the organization removed malicious scripts, hardened its file upload controls, and patched the SQL injection issue. SuperINN also rotated the encryption keys used to protect stored payment information. These actions were taken to restore security and prevent further unauthorized access to guest data.

Incidents

1 incident linked to this organisation.

CSIDB