Skip to main content
Grand luxury hotel entrance at twilight with warm light and elegant doors
News ·

Unsaflok Incident: Strengthening Security and Building Trust

2 min read

Security researchers reported Unsaflok, a group of vulnerabilities affecting certain Dormakaba Saflok hotel lock configurations. The issue was first reported privately to Dormakaba in September 2022 and disclosed publicly in March 2024. According to both the researchers and Dormakaba, they were not aware of real-world exploitation at the time of their public statements.

The researchers demonstrated that an attacker with access to an active or expired property card and suitable read/write equipment could create forged credentials for affected installations. This was not a malicious software update or a hidden backdoor. The risk depends on the lock model, system configuration, software and whether Dormakaba’s Enhanced Security measures have been applied.

What hotels should do

Hotels should use Dormakaba’s official self-assessment and contact its hospitality security support team. Depending on the installation, remediation may include software updates, lock or encoder updates, replacement hardware, new cards and coordination with connected property-management systems. Staff should also follow established card-control procedures and promptly investigate missing credentials or unusual access events.

Dormakaba’s guidance is installation-specific. Replacing cards alone does not remediate a vulnerability in a lock system, and a card with a different chip cannot be assumed to work safely with an existing reader or encoder.

How PrintPlast supports a card migration

PrintPlast manufactures credentials to a hotel’s confirmed chip, memory, frequency, dimensions and print requirements. For a remediation or migration project, the lock-system provider should first define the approved credential specification. We can then produce samples for validation with the property’s actual readers and encoders before volume production. Security ultimately depends on the complete access-control system, including chip configuration, key management, software, hardware and operating procedures—not on the printed card body alone.

For current technical guidance, consult the Unsaflok research disclosure and Dormakaba Hospitality Security Support.

Dormakaba and Saflok are third-party marks used only to identify the affected systems. PrintPlast is an independent card manufacturer and is not affiliated with or endorsed by their owners.