Laura Hobson, Co-Founder & COO, YoursGlobal · · 6 min read
More than three million hotel and apartment doors have been associated with NFC keycard cloning vulnerabilities. That is a real number describing real systems, but it is not a reason to panic. It is a reason to understand how a hotel lock works and what you can do about it.
Many hotels use RFID or NFC locks manufactured by dormakaba. Some older systems use MIFARE Classic cards, which have known cryptographic weaknesses.
Dormakaba began upgrading systems in late 2023, but WIRED reported that only 36% of installed Safloks had been updated at the time of disclosure.
If a hotel is using an older dormakaba Saflok system with MIFARE Classic cards, the lock may be vulnerable. If the property has upgraded to newer cards such as MIFARE DESFire or uses a different system, the situation may be different.
YourSweep can scan your keycard and help identify the card type. If it appears vulnerable, you can request a room change, ask about additional locks, or decide whether you are comfortable with the risk.
Hotels are upgrading. The vulnerability is public, and manufacturers are responding. The process is slow because it can require new hardware, new keycards, front desk software updates, and changes to third-party integrations. In the meantime, awareness is your best defense.
Laura Hobson, Co-Founder & COO, YoursGlobal