Hackers are exploiting legitimate hotel reservations from over 350 properties worldwide to launch convincing spear-phishing campaigns. The targeted attacks use genuine booking details to bypass user skepticism.
Scammers have found a new angle for credential theft: your actual hotel reservations. By accessing customer data from more than 350 hotels globally, attackers are crafting highly personalized phishing messages that reference real bookings, making them far more likely to succeed.
How the scam works
The attacks typically arrive as emails mimicking hotel confirmation updates or account notifications. Because the messages reference genuine reservation details—booking dates, confirmation numbers, guest names—recipients are more inclined to click malicious links or provide sensitive information.
Once clicked, victims land on fake login pages designed to steal credentials. These can then be used to compromise email accounts, payment methods, and other linked services.
The scope
Security researchers have identified compromised data from hospitality chains across multiple continents. The breadth of affected properties suggests either a widespread vulnerability in hotel booking systems or data broker networks selling stolen reservation information to scammers.
What to watch for
Legitimate hotel communications typically:
- Come from official hotel domains or recognized booking platforms
- Don't request passwords via email
- Include verifiable contact information
If you receive unexpected hotel-related emails, verify independently by logging directly into your booking account or calling the hotel's main line—not numbers provided in the email.
Protection steps
Enable two-factor authentication on hotel loyalty accounts and email. Use unique, strong passwords for travel bookings. Consider using a password manager to avoid reusing credentials. Monitor bank and credit statements for unauthorized charges.
Hotels should review security protocols and notify affected guests of potential data exposure. Customers should remain vigilant: the more personal the phishing message, the more suspicious it warrants.
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.
The FBI is investigating a possible security breach at an ID verification company that may have exposed driver's license scans belonging to millions of Americans. The agency confirmed the investigation to Bloomberg News on Thursday.
Attackers compromised Coder's Cloudflare infrastructure and injected malicious Terraform modules designed to steal credentials. The unauthorized registry servers delivered the infected packages to users.
A US senator has called on the NSA to provide official guidance on virtual private network selection and usage, citing confusion over the growing array of available options.