Tackling the Top 4 Fraud and Abuse Challenges this Holiday Season

Last holiday season, the headlines were all about the excess supply and glut of inventory that retailers had to sell off quickly to capture revenue amidst tight competition and waning consumer sentiment. While this year has so far presented new macroeconomic pressures — which some argue might be getting worse — retailers have continued to…

Read More

Member Spotlight: Michael Francess

Michael Francess is the senior manager of cybersecurity advanced threat and response at Wyndham Hotels & Resorts. We were able to talk with Michael about his fascination with cybersecurity during his youth, role at Wyndham, and how the RH-ISAC community has impacted him. Tell us about yourself and your background. I have been with Wyndham…

Read More

Cybercrime Never Takes a Vacation: Cybersecurity in the Hospitality Industry

The Trustwave SpiderLabs team conducted a multi-month investigation into the cyber threats facing the hospitality industry worldwide and has released a detailed report displaying how threat actors conduct attacks, the methodologies used, and what organizations can do to protect themselves from specific types of attacks. The report, 2023 Hospitality Sector Threat Landscape: Trustwave Threat Intelligence…

Read More

How to Stay Secure Amid AI Mania

Picture this: A French-speaking security researcher finds a critical vulnerability in a major U.S. retailer’s mobile app. They draft an email warning, but they run it by an AI chatbot to fix English language snafus before notifying the company. Now imagine an attacker has been prowling the same large language model app for sensitive information….

Read More

MetaStealer Family of Go Infostealers Targeting Businesses Using macOS

On September 11, 2023, SentinelOne researchers reported the technical details a campaign targeting unspecified businesses that operate macOS in their environments with a series of infostealers written in Go they dubbed the “MetaStealer” family. Context According to the report, the campaign has been “proactively targeting macOS businesses by posing as fake clients in order to…

Read More

The RH-ISAC Cyber Intelligence Summit Delivers Unmatched Content

The RH-ISAC Cyber Intelligence Summit agenda is brimming with keynote and breakout sessions showcasing an array of cybersecurity’s top experts. From October 2 – 4 in Dallas, Texas, attendees can partake in sessions designed to spark discussions, develop connections, and explore solutions to prominent issues cybersecurity practitioners face while working in the retail and hospitality…

Read More

“Spacecolon” Toolkit Used to Target Multiple Industries with Scarab Ransomware, including Hospitality and Entertainment Organizations

Context On August 22, 2023, researchers at ESET released the technical details of the Spacecolon toolset, which they observed being leveraged in multiple campaigns to deploy the Scarab ransomware against multiple industries. According to the report, the campaigns are not specifically targeted, but are opportunistic in nature. Known targets include “a hospital and a tourist…

Read More

Member Spotlight: Charles Fedorko

Charles Fedorko is the director of IT security at Sage Hospitality Group. We were able to sit down with Charles to talk about his role, journey leading to his career in cybersecurity, the current cybersecurity landscape surrounding the hospitality industry, and the upcoming RH-ISAC Summit in October. Tell us about yourself and your background. How…

Read More

Retail & Hospitality ISAC Announces Agenda for Cyber Intelligence Summit

Vienna, VA, (August 17, 2022) — The Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) has announced the agenda for the upcoming RH-ISAC Cyber Intelligence Summit. The conference, scheduled to take place on October 2-4 in Dallas, Texas, brings together industry leaders, cybersecurity practitioners, and thought influencers for a three-day event that explores the latest…

Read More

How Organizations Can Prepare to Comply with New SEC Cybersecurity Reporting Rules

In July of 2023, the U.S. Securities and Exchange Commission, commonly known as the SEC, adopted new rules necessitating the disclosure of material cybersecurity incidents and related risk management, strategy, and governance. One of the most notable requirements of the new regulations is that companies must report a cybersecurity incident within four business days after…

Read More