IHG data hack was done "for fun"

An image of security icons for a network encircling a digital blue earth.
(Image credit: Shutterstock)

The cyber attack on the Intercontinental Hotels Group (IHG), which operates the Holiday Inn brand, was reportedly carried out "for fun".

The perpetrators of the attack, who claimed to be a couple from Vietnam, told the BBC the "attack was originally planned to be a ransomware but the company's IT team kept isolating servers before we had a chance to deploy it".

The hackers, who also go by the name of "TeaPea", then decided to "have some funny" before switching to a "wiper attack", a variety of attack which deletes the user's data permanently without ransoming it for financial gain. 

IHG attack

The full scope of the incident has not yet been revealed, however, IHG said in a statement that its booking channels and other applications had been "significantly disrupted".

The hackers told the BBC they used the widely-used password "Qwerty1234" to access the company's most sensitive databases.

Before this, TeaPea gained access to the IHG IT systems by tricking an employee into downloading malicious software via a phishing email.

They also had to bypass an additional security prompt message sent to the worker's devices as part of a two-factor authentication system.

The hackers maintained that they didn't steal any customer data, though they did manage to access some corporate data such as emails according to the sources.

Despite the attack turning malicious, the original motivations behind it were economic.

"We don't feel guilty, really," they told the BBC. "We prefer to have a legal job here in Vietnam but the wage is an average $300 per month." 

They added: "I'm sure our hack won't hurt the company a lot."

In contrast to some of the hacker's claims, an IHG spokesperson told the BBC that hackers would have needed to have evaded "multiple layers of security" to get into systems.

She said: "IHG employs a defence-in-depth strategy to information security that leverages many modern security solutions". 

Wiper attacks are often used by national states for political ends due to the chaos they can cause.

The US National Security Agency (NSA) has alleged that the Russian government used the “AcidRain” malware to disrupt Viasat's satellite network via data deletion around the time of their attack on Ukraine.

  • Scared of ending up as the next high-profile cyber attack? Checkout our guide to the best endpoint protection

Will McCurdy has been writing about technology for over five years. He has a wide range of specialities including cybersecurity, fintech, cryptocurrencies, blockchain, cloud computing, payments, artificial intelligence, retail technology, and venture capital investment. He has previously written for AltFi, FStech, Retail Systems, and National Technology News and is an experienced podcast and webinar host, as well as an avid long-form feature writer.

Read more
Ransomware
Millions of hotel guest reservations leaked in Otelier data breach
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
sewage water treatment
Southern Water denies claims it offered $750,000 ransom to ransomware hackers
ransomware avast
AI is helping hackers get access to systems quicker than ever before
Flags of Iran, China, Russia and North Korea on a wall. China North Korea Iran Russia alliance
Cybercrime is helping fund rogue nations across the world - and it's only going to get worse, Google warns
Latest in Security
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units