SANS Internet Storm Centre reported on 16 September 2026 that internet scans were targeting applications associated with hotel and hospitality systems. The activity began on 15 September and continued the following day, using the user agent `Farez-Sorter/1.0`. Requests included paths such as `/PIAF-HMS/`, `/admin/`, `/admin/config.php`, `/ucp/`, `/hms/` and `/hotel/`.
The scans were traced to a single source IP address, 94.102.49.125, associated with IP Volume (AS202425), which the report describes as often being considered a bulletproof hoster.
The initial request targeted PIAF-HMS, the PBX in a Flash Hospitality Management System. SANS researcher Johannes Ullrich said the project’s last update, adding a licence file, was about 10 years ago and considered it abandoned. He also noted a SQL injection vulnerability reported a few months earlier, and said a brief code review indicated further issues, including apparent shortcomings in input validation and potentially absent authentication and access controls.
The report does not confirm that any system was compromised or that the scans led to exploitation. Ullrich highlighted that hotel systems can expose valuable personal data and, in some cases, have been abused for attacks against guests. He suggested the focus on PBX systems might enable attackers to appear to call from within a property, but presented this as a possibility rather than an established motive. Operators should check for requests matching the listed paths and source address, and review any exposed or abandoned hospitality and PBX applications.