The Westin Washington DC City Center was one of the 20 hotels hit by the attack. Photo by the Westin.

WASHINGTON, DC—As far as cyber hacks go, the Norwalk, CT-based HEI Hotel & Resorts breach doesn't rank very high in terms of daring or potential catastrophe; at least not compared to the current one dominating headlines. An unknown group of cyber criminal group is claiming to have stolen US government hacking tools from an organization affiliated with the National Security Agency. Supposedly these tools are on sale right now — available to the highest bidder.

But then again, ask a guest who had stayed at one of the affected hotels during the time period the malware was active what his or her thoughts are about the breach. Or ask a security expert that has been following the chain of cyber thefts at hotels for the last two years, most of which have occurred through the same point of vulnerability.

The perspective changes a bit.

Recommended For You

Want to continue reading?
Become a Free ALM Digital Reader.

Once you are an ALM Digital Member, you’ll receive:

  • Breaking commercial real estate news and analysis, on-site and via our newsletters and custom alerts
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical coverage of the property casualty insurance and financial advisory markets on our other ALM sites, PropertyCasualty360 and ThinkAdvisor
NOT FOR REPRINT

© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.

Erika Morphy

Erika Morphy has been writing about commercial real estate at GlobeSt.com for more than ten years, covering the capital markets, the Mid-Atlantic region and national topics. She's a nerd so favorite examples of the former include accounting standards, Basel III and what Congress is brewing.