Categories: WORLD

US spy agency asked hacker to steal foreign diplomats’ data, journalists claim

The alleged perpetrator, dubbed “Andrew,” stole the “details of thousands of hotel reservations” across Middle Eastern countries, according to a report published on Wednesday by Dutch newspaper NRC Handelsblad. The bombshell article was citing accusations made in a new book by its journalists.

An employee at the joint US-Dutch firm’s Amsterdam headquarters discovered the hack by accident after coming across an unauthorized access via a poorly secured server. The breach gave Andrew and their associates access to customer data, travel plans, and unique user personal ID numbers (PINs).

The hack was verified by three former security specialists and a manager at the company at the time of the breach. Enlisting US private investigators, Booking.com’s security team determined two months later that Andrew worked for a company that carried out assignments from US intelligence services. The actual agency involved in the incident was not identified.

Although Booking.com alerted the Dutch intelligence agency AIVD, it apparently did not notify users or the Dutch Data Protection Authority (AP) – later justifying this decision on the grounds that it was not legally required to do so at the time. The hack predated the implementation of the EU’s General Data Protection Regulation (GDPR), which requires data leaks to be disclosed to state authorities.

However, unnamed sources revealed that the company’s IT specialists were uncomfortable with the management’s decision – based on advice from London-based law firm Hogan Lovells – to keep the breach under wraps. Under the applicable privacy laws of the time, the company was still required to inform affected persons when the data theft “would likely have adverse effects on the private lives of individuals.”

Claiming that “no sensitive or financial information” was accessed in the leak, the company said in a statement that its “leadership at the time worked to follow the principles of the Dutch Data Protection Act.” Under that law, companies were advised to issue a notification “only if there were actual adverse negative effects on the private lives of individuals, for which no evidence was detected.”

The report comes almost exactly eight years after NSA whistleblower Edward Snowden revealed the existence of a special program called ‘Royal Concierge’ run by British spy agency GCHQ that conducted surveillance on more than 350 hotels hosting foreign diplomats and officials.

While the Snowden documents did not identify any specific reservation websites, a former Booking.com security specialist told the Dutch paper that it would be “crazy if [it] weren’t on that list.”

If you like this story, share it with a friend!

© 2021, paradox. All rights reserved.

paradox

Share
Published by
paradox

Recent Posts

Russia issues military ultimatum to UK

Moscow will retaliate against British targets in Ukraine or elsewhere if Kiev uses UK-provided missiles…

19 hours ago

Zelensky can’t ‘mobilize God’ – Russian church

Ukrainian President Vladimir Zelensky cannot enlist God in Kiev’s fight against Moscow, the Russian Orthodox…

1 day ago

Ukrainians are God’s chosen people – Zelensky

Ukrainian President Vladimir Zelensky has proclaimed that God is an “ally” of Ukraine in the…

2 days ago

Israel ready for temporary truce with Hamas – Netanyahu

Israel is willing to pause its military offensive in Gaza if Hamas releases all the…

2 days ago

Some EU states still consider Russia ‘good friend’ – Borrell

The EU’s top diplomat, Josep Borrell, has admitted that not every member state agrees to…

2 days ago

WATCH Russian forces destroy US-made armor

Russia’s Defense Ministry has published a video clip from the front line with Ukraine showing…

3 days ago