An investigation has uncovered a spyware application running on hotel computer systems used for guest check-ins at various Wyndham hotel locations in the United States, according to a report by TechCrunch.
The spyware known as pcTattletale was found to be surreptitiously capturing and leaking screenshots from hotel booking systems, inadvertently making sensitive guest information accessible online due to a software vulnerability.
Consumer spyware apps have previously been implicated in exposing private data due to faulty security, with pcTattletale being implicated in a similar exposure incident before. These lapses have sometimes led to governmental regulatory interventions in response to the privacy risks posed.
Sensitive Data at Risk: Guest and Reservation Information Leaked
The application pcTattletale can remotely provide a controller with access to Android and Windows devices. Its makers assert the software is undetectable on workstations. A critical flaw, however, allows unauthorized users to download these captured screen images from the spyware’s servers.
Security specialist Eric Daigle discovered the compromised systems during a broader inquiry into such spyware, sometimes known as “stalkerware” due to its use in silently monitoring individuals. Daigle alerted pcTattletale but received no response, and the vulnerability remains unfixed.
TechCrunch reviewed screenshots showing guest names and reservations via a Sabre-powered web portal at two Wyndham hotels that included partially visible payment card numbers. Another image revealed access to a third hotel’s check-in operating a Booking.com management portal.
Circumstances regarding the spyware’s deployment are unclear, as are the motives behind it, whether for employee monitoring or otherwise. TechCrunch has not disclosed the names of the hotels to prevent potential backlash against hotel staff.
Concerning the incident, Wyndham, a franchised organization, has implied that the individual hotels operate independently. Booking.com clarified that their systems had not been compromised but acknowledged the pervasive threat of cybercrime on hotel partners’ systems.
Concealed Surveillance and Its Marketing
Stalkerware applications, under the guise of lawful tracking of children or employees in the US, may also suggest or endorse their use for clandestine surveillance, such as monitoring a spouse without consent—a criminal action.
pcTattletale openly suggests its product for monitoring spouses with suspicions of infidelity. Customers are offered assistance in covertly installing the spyware through a remote installation service promoted as leaving “All tracks covered.”
Although requiring physical access to install, pcTattletale touts a quick setup for its Windows application, which TechCrunch verified. The company’s founder, Bryan Fleming, has not responded to requests for comment on the issue.
For any further reporting or documentation submissions, this reporter can be reached through Signal, WhatsApp, or email. Documents may also be submitted through SecureDrop for confidentiality.
FAQs about the Spyware Found on US Hotel Check-in Computers
- What is pcTattletale?
pcTattletale is a spyware application that can remotely capture and view data from an Android or Windows device without the user’s knowledge, ostensibly for monitoring children or employees. - How was the spyware discovered at the hotels?
A security researcher found the running spyware while investigating consumer spyware applications, also known as stalkerware. - What information was exposed?
The spyware leaked screenshots of hotel booking systems that included guest names, reservation details, and partial payment card numbers. - Has the flaw in pcTattletale been fixed?
At the time of the report, pcTattletale had not responded to the security researcher’s warnings, and the flaw remained unresolved. - Were the hotels aware of the spyware?
One hotel management confirmed they were unaware of the spyware’s presence on their systems. The other hotels did not respond to inquiries. - Is this type of spyware legal?
While there can be legal uses for monitoring software, such as parental control over children’s devices, using it for unauthorized spying, such as on adults without their consent, is unlawful.
Conclusion
The presence of spyware such as pcTattletale on hotel check-in systems is a cause for concern that highlights the darker side of consumer-grade monitoring software and the vulnerabilities it can pose to privacy and security. With the lines between legitimate monitoring and covert spying often blurred, it is important for stakeholders, from software developers to individual users, to be vigilant about responsible usage and to address security issues promptly to protect against potential misuse and data breaches.










































