
Summary created by Smart Answers AI
Table of Contents
In summary:
- PCWorld highlights essential privacy tools after a hotel data breach exposed the author’s personal information including name, email, and stay dates.
- Virtual credit card numbers from banks like Capital One and Citi protect against financial theft, while email masks prevent phishing attacks.
- Using virtual phone numbers or Google Voice helps avoid data broker profiling and protects your real contact information from future breaches.
I was on vacation when I got the ping. It was an email that started: “We are writing to inform you that our hotel management system has been subject to unauthorized access.” I actually couldn’t even read it at first—the text was in the hotel’s native language.
Turns out, hackers had gotten into the guest database of a place I’d booked for later in the trip. The data leaked included my name, email address, and dates of stay.
Reading the brief, curt overview made me mad. But not at the hotel. At myself. I knew immediately a few things I could have done better—and they’re things I recommend you do, too.
1) I should have hid my email address
I often use email masks—a kind of codified, anonymized version of email aliases. (Think [email protected] or [email protected].) These are linked to your real email address. The idea is you register for a website, service, or app with an email mask, which then forwards on the email to your actual account.
I was in a hurry the day I booked this hotel, and so I skipped using an email mask. But having done so would have saved me from having to be extra watchful for phishing messages. Not the way I wanted to spend my time off.
2) A virtual phone number would have helped, too
You can hide your phone number just like you can an email address—phone masks exist too. You generate these virtual numbers through services like Firefox Relay or Surfshark, any time you have to give such contact info. The benefit is twofold: Hackers and data brokers alike can’t build a detailed profile on you with that info, when it’s inevitably lost or sold.
An alternative is to use a Google Voice number, which at least hides your real number. That reduces your exposure to spam texts/calls and makes SIM jacking a bit harder. But it doesn’t help as much to reduce profiling if you use it everywhere as your “junk” number—and so while I used one here, I wish I’d gone with a phone mask instead. It again simplifies having to look out for phishing messages.
3) A virtual credit card number
The email about the data breach was quick to assure that no credit card data had been stolen, but I still kicked myself anyway for using the same card I’d brought with me on vacation. Had financial info been leaked, I could’ve had a big headache trying to cancel the card and get a new one shipped to me.
In retrospect, I would have been smarter to use a virtual credit card number, which some banks offer as a free service. (Ex: Capital One and Citi.) You generate them per merchant, with shorter expiration dates than your normal card. If the info ever gets stolen, it’s easy to cancel that number.
Worried about your hotel reservation matching the card you use in person? Use a secondary credit card. (But I haven’t encountered a hotel that expects that kind of matching in years.)
You can’t take a vacation from hackers
So why bother with hiding all your normal info? I’m a realist—while I could be irritated that the hotel didn’t have better security protocols, most businesses just don’t have those resources. I don’t like it, but that’s how it is right now.
Since we don’t have control over how easily our data is lost or stolen, the best defense is a good offense. If the best way scammers have to bilk money from us is to build detailed profiles, make that job harder.