Most travelers check into a hotel room, tap their keycard on the door, hear that reassuring click, and feel safe. It’s a reasonable assumption. Hotels invest heavily in access control, surveillance, and security protocols. The problem is that one of the most trusted features in any guest room – the electronic door lock and its keycard – has a vulnerability story that’s been quietly unfolding for years, and the details are more unsettling than most guests realize.
This isn’t meant to alarm you out of enjoying travel. It’s meant to help you understand what’s actually going on with hotel room security, so you can make smarter decisions on the road.
The Keycard Lock: A Reassuring Illusion

Hotels invest heavily in surveillance, access control software, and premium electronic locks. Yet one of the most overlooked security risks sits in guests’ pockets every single day: the RFID key card. Most guests never think twice about that little piece of plastic, trusting it the same way they’d trust a deadbolt at home.
A hotel can have the most advanced lock system available and still be exposed if the key cards being issued contain low-security or outdated RFID chips. Most RFID hotel key cards look identical on the outside. There’s no way to know, just by looking, whether your card is truly secure or a weak link in the chain.
The Unsaflok Revelation: Three Million Doors at Risk

Security researchers discovered vulnerabilities in dormakaba’s Saflok electronic locks, which would allow hackers access to rooms and residences in a matter of seconds. Saflok, an electronic RFID lock, is installed on three million doors on over 13,000 properties worldwide, mostly hotels and multi-family housing environments.
The flaws, dubbed Unsaflok, were first discovered and reported to dormakaba in September of 2022 and publicly disclosed in March 2024 by a team of security researchers. The vulnerability affects three Saflok systems – System 6000, Ambiance, and Community – and at least five Saflok lock series, including Confidant, RT, Saffire, Saflok MT, and Quantum.
How the Hack Actually Works

The technique starts with obtaining any keycard from a target hotel – either by booking a room or grabbing a keycard out of a box of used ones – then reading a certain code from that card with a $300 RFID read-write device, and finally writing two keycards of their own.
An attacker only needs to read one keycard from the property to perform the attack against any door in the property. This keycard can be from their own room, or even an expired keycard taken from the express checkout collection box. The simplicity of that entry point is what makes it particularly sobering.
The Slow Fix: Most Vulnerable Locks Still Unpatched

As of March 2024, only about a third of the impacted locks had been updated or replaced. At the time of the disclosure, not all impacted locks had been updated or replaced. That’s a significant gap between the discovery of a serious flaw and its resolution across the industry.
Upgrading each hotel is an intensive process. All locks require a software update or have to be replaced. Additionally, all keycards have to be reissued, front desk software and card encoders have to be upgraded, and third-party integrations have to be addressed. In other words, fixing this isn’t a quick firmware push – it’s a logistical undertaking that takes months or longer per property.
Card Cloning: The Broader, Ongoing Threat

Despite advancements in technology, RFID hotel key cards remain targets for various sophisticated attacks. Card cloning is one of the most common threats. Attackers use specialized devices to copy card data and create duplicates.
Systems using MIFARE Classic or UID-based authentication are particularly vulnerable. From a card security standpoint, cloning attacks represent a fundamental risk in many existing hotel installations. Criminals can scan and emulate RFID keycards, enabling unauthorized room access. The tools required are inexpensive and widely available online.
The Hotel Safe: Also Not What It Seems

All hotel room safes have a backdoor or special way to access them so the staff can get into the safe in case a guest forgets the code, or loses the key to the safe, or electronics fail. Some safes may use a master key or card while others may have a special override code to open the door.
There’s also a risk if override codes aren’t regularly updated. While intended for emergency access, many safes still use factory-set codes that can be found online. In these cases, someone with the default code could open the safe without any visible signs of entry. Some hotel safes are small, lightweight, and often not bolted down, making them easy to remove entirely. A thief who gains access to your room could simply walk off with the safe and attempt to open it later.
The Staff Access Problem

Even though you’re issued a hotel key, that’s not really a guarantee of safety. Hotel employees often have access to rooms, even when they’re locked, and people from outside the company can come in while housekeepers are cleaning and act like it’s their room.
According to Mike Moske, a certified lodging security director and private investigator with 25 years of experience managing hotel and resort security, the staff perpetrates roughly 60 to 70 percent of hotel theft, not someone from outside. The vulnerabilities of hotel safes are connected to how the safe is installed and who has access to it. That combination of physical access and weak safeguard design is worth taking seriously.
Limited Monitoring Makes Problems Harder to Detect

The lack of real-time monitoring means that if a master key is lost or cloned, it cannot be instantly revoked across the entire property. Limited logging and audit trails make it difficult for security teams to identify suspicious patterns, such as a single card being used to access multiple rooms in a short timeframe or a door being opened during unusual hours.
Without a robust backend that integrates with the Property Management System, hotels are essentially flying blind. Unlike safes that are monitored by security cameras or require check-ins, hotel safes are often not monitored. If a valuable item goes missing, it can be difficult to prove theft.
Why Cost Pressures Keep Weak Systems in Place

In a highly competitive industry with thin margins, procurement departments are often under pressure to minimize costs. This frequently leads to the selection of low-cost, low-security RFID chips from unverified suppliers. While a few cents saved per card may seem insignificant, the long-term liability risks are enormous.
One reason many hotels continue using less secure chips is cost. High-security RFID cards are more expensive, and upgrading infrastructure requires additional investment. However, the long-term cost of security incidents often outweighs the initial savings. It’s a familiar tension in any industry – short-term savings versus long-term exposure.
What Travelers Can Actually Do

Always engage the deadbolt lock when you’re in the room. Deadbolts are generally more resistant to forced entry than the standard lock on the door handle. Most hotel rooms also have an additional security latch – ensure it is fastened whenever you are inside the room to prevent the door from being fully opened from the outside.
If a lock hasn’t been updated, experts say the deadbolt won’t help since it’s connected to the keycard, so use your door’s key chain instead. For added security, consider using a portable door lock, which can be easily installed and removed, preventing the door from being opened even if someone has a key. For valuables, don’t leave large amounts of cash or irreplaceable jewelry in your room, and make sure you carry copies of your passports with you.
A Measured Final Thought

None of this means hotels are dangerous places to stay. For the vast majority of travelers, a mainstream hotel stay is entirely uneventful. Recent crime statistics in major travel markets suggest that overall violent crime eased from pandemic-era peaks. For most travelers, the risk of being caught in a serious violent incident inside a mainstream hotel remains relatively low, but the perception of danger is heightened by social media and continuous news coverage.
What the research does suggest is that the room feature most guests trust without question – the electronic door lock and keycard system – deserves more scrutiny than it gets. The good news is that awareness itself is a form of protection. Knowing how these systems work, what their weaknesses are, and how to layer your own precautions on top of them puts you in a far stronger position than simply tapping a card and assuming the rest will take care of itself.
AI Disclaimer: This article was created with the assistance of AI tools and reviewed by a human editor.