Security for PMS, booking engine, RFID locks, guest Wi-Fi and OTA integrations.
Why now
Hotels are a golden target: passports, cards, IDs, location data and consumption patterns of guests — including executives traveling for business. RFID locks cloned with $50 gadgets, booking engines integrated with OTAs, legacy PMS. Ransomware shuts down check-in in high season — million-dollar losses.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Unauthorized access to reservations, rate manipulation, folio fraud and overnight adjustments.
Card cloning, master key, proximity bypass, SDR attack.
Captive portal, segregation, MitM against executives on corporate travel.
Booking.com, Expedia — sync, rate manipulation, malicious overbooking.
Improper charges, improper safe opening, consumption fraud.
Point manipulation, miles/cashback fraud, upgrade abuse.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Demand from luxury hotel chains in Brazil, Portugal and Italy.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. We audit RFID/NFC with SDR and Proxmark, replay/clone and proximity attack. Work is done with cards provided by the client.
We don't store real PII. We work in mirror environments and, when needed, with anonymized or synthetic data.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.