
Ransomware at Puerto Rico hotels: lessons we cannot ignore
When the reservation system goes dark on a Friday night, the cost is not just technical. We break down what failed and what a local hospitality operation can do today.
In 2022 and 2023, several hotels and boutique chains in the Caribbean — including properties in Puerto Rico — showed up in incident patterns similar to those Brian Krebs frequently documents on Krebs on Security. It was not always a spectacular breach: often it was forgotten remote access, an untested backup, or a POS vendor reusing credentials.
The pattern is predictable
The pattern is predictable. Ransomware enters through exposed RDP or phishing aimed at accounting. It encrypts reservation servers and, in worst cases, electronic key systems. The front desk goes back to paper while the GM negotiates under pressure. For an 80-room hotel in Condado or Isla Verde, two offline days in peak season can exceed the ransom demand.
What frustrates us as local consultants is seeing the same t
What frustrates us as local consultants is seeing the same three mistakes: backups in the same Active Directory domain as production servers, no MFA on admin accounts, and no guest communication plan if card data leaks. CISA publishes clear hospitality-sector guidance; few mid-size properties have read it.
Our practical recommendation for hotel SMBs: segment networks (POS separate from office), test backup restores quarterly with a documented scenario, and retain minimal incident-response support before you need it. Cyber insurance helps, but without evidence of basic controls many policies do not pay.
Puerto Rico is not invisible on the threat map. We are a tourism hub with a defined high season — that makes us an opportunistic target. The good news: hardening a mid-size hotel environment is achievable in weeks, not years, if you prioritize correctly.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


