Relevance: primary · Type: event
Confidence95%
Travelers’ information and booking details may have been stolen from at least 350 hotels, vacation rentals, motels, and guesthouses in 50 different countries.
Relevance: primary · Type: action
Confidence95%
Stolen trip details, such as booking names and reservation information, are being used by cybercriminals to create highly targeted phishing messages to steal credit card information.
Relevance: supporting · Type: event
Confidence95%
Phishing websites analyzed by Norton included hotel names, victim-specific prices, and specific check-in and check-out details.
Relevance: supporting · Type: event
Confidence95%
Germany had the most hotels potentially affected by customer data compromise, followed by France, the U.K., Italy, Spain, and the U.S.
Relevance: supporting · Type: background
Confidence90%
The 350 accommodations named in scam messages have an estimated peak capacity of around 80,000 guests.
Luis Corrons, research lead at Gen Digital
Relevance: supporting · Type: background
Confidence95%
Most of the accommodations involved are small- and medium-size hotels.
Relevance: supporting · Type: event
Confidence95%
Americans lost more than $200 million due to successful phishing attempts in the previous year.
Relevance: supporting · Type: event
Confidence90%
Norton began its investigation into hotel-linked fraud in December after identifying a phishing message on WhatsApp impersonating Booking.com.
Relevance: supporting · Type: event
Confidence90%
The phishing message listed specific hotel reservation dates and asked the recipient to click a link to confirm details.
Relevance: supporting · Type: event
Confidence90%
The link in the phishing message led to a fraudulent website that included a chatbot sending entered credit card details directly to hackers.
Relevance: supporting · Type: action
Confidence85%
Hackers may have obtained vacation booking details by accessing hotel systems via phishing or through third-party booking services.
Relevance: supporting · Type: action
Confidence85%
Hackers may have sent malware-laced emails or files to hotels to obtain login credentials.
Relevance: supporting · Type: background
Confidence90%
Previous Norton research published in March mentioned both Booking.com and hotel-management-system CloudBeds.
Luis Corrons, research lead at Gen Digital
Relevance: supporting · Type: event
Confidence90%
Researchers obtained phishing messages received by accommodation staff.
Luis Corrons, research lead at Gen Digital
Relevance: supporting · Type: quote
Confidence90%
Not every observed phishing message was definitively caused by a direct compromise of a hotel’s internal systems.
Relevance: supporting · Type: background
Confidence85%
Phishing messages could have been sent using information from data breaches unrelated to the travel industry.
Luis Corrons, research lead at Gen Digital
Relevance: primary · Type: quote
Confidence95%
Criminals are weaponizing real reservation context to push travelers into fake verification or payment flows.
Luis Corrons, research lead at Gen Digital
Relevance: supporting · Type: action
Confidence90%
Norton has not published the full list of potentially compromised hotels but has contacted Europol about its findings.
spokesperson
Relevance: supporting · Type: quote
Confidence95%
A Europol spokesperson declined to comment, stating that Europol does not discuss its operational activity.
spokesperson
Relevance: supporting · Type: quote
Confidence95%
Booking.com says it continues to strengthen its defenses to reduce risk and limit opportunities for bad actors to target accommodation partners and customers.
Relevance: supporting · Type: action
Confidence95%
Cloudbeds says it has not been breached and that the attacks are credential-phishing campaigns targeting hotel staff and then customers.
Aaron Ownbey, vice president of engineering at Cloudbeds
Relevance: supporting · Type: quote
Confidence95%
Aaron Ownbey, vice president of engineering at Cloudbeds, says the reason these scams are effective is that attackers know exactly who the guest is, when they’re arriving, and what they paid.
Aaron Ownbey, vice president of engineering at Cloudbeds
Relevance: supporting · Type: quote
Confidence95%
Aaron Ownbey says the hospitality industry needs to collectively raise the security baseline through better staff training, wider adoption of phishing-resistant authentication, and tighter controls on guest data access and export.
Don Smith, vice president of threat research at Sophos
Relevance: supporting · Type: background
Confidence90%
Smaller hotels are less likely to implement security best practices such as multifactor authentication for staff members.
Relevance: supporting · Type: event
Confidence90%
In one incident handled by Sophos, a cybercriminal emailed a hotel claiming to have lost a passport during a recent stay.
Relevance: supporting · Type: event
Confidence90%
In a follow-up message, the attacker included a link to a photo of the passport that, when clicked, downloaded a file containing the Vidar info stealer malware.
Relevance: supporting · Type: event
Confidence90%
Days after the malware was deployed, fraudulent messages were sent to customers from the hotel’s Booking.com account, and customers reported losing money.
Don Smith, vice president of threat research at Sophos
Relevance: supporting · Type: quote
Confidence95%
Don Smith says threat actors love context because it makes phishing lures more compelling.
Don Smith, vice president of threat research at Sophos
Relevance: supporting · Type: quote
Confidence95%
Don Smith says it is very hard to avoid reacting and clicking on something to reduce stress during a potentially stressful travel experience.
Luis Corrons, research lead at Gen Digital
Relevance: supporting · Type: quote
Confidence95%
Luis Corrons says the inclusion of real information in phishing messages makes it harder to distinguish legitimate messages from scams.
Luis Corrons, research lead at Gen Digital
Relevance: supporting · Type: quote
Confidence95%
Luis Corrons advises contacting the hotel or vacation rental directly through another means if there is doubt about a message’s legitimacy.
Luis Corrons, research lead at Gen Digital
Relevance: primary · Type: quote
Confidence95%
Luis Corrons says that even if the data in a message is real, it does not mean the message itself can be trusted.
forum Comments (0)
No comments yet. Be the first to comment.