Hackers are exploiting legitimate hotel reservations from over 350 properties worldwide to launch convincing spear-phishing campaigns. The targeted attacks use genuine booking details to bypass user skepticism.
Scammers have found a new angle for credential theft: your actual hotel reservations. By accessing customer data from more than 350 hotels globally, attackers are crafting highly personalized phishing messages that reference real bookings, making them far more likely to succeed.
How the scam works
The attacks typically arrive as emails mimicking hotel confirmation updates or account notifications. Because the messages reference genuine reservation details—booking dates, confirmation numbers, guest names—recipients are more inclined to click malicious links or provide sensitive information.
Once clicked, victims land on fake login pages designed to steal credentials. These can then be used to compromise email accounts, payment methods, and other linked services.
The scope
Security researchers have identified compromised data from hospitality chains across multiple continents. The breadth of affected properties suggests either a widespread vulnerability in hotel booking systems or data broker networks selling stolen reservation information to scammers.
What to watch for
Legitimate hotel communications typically:
- Come from official hotel domains or recognized booking platforms
- Don't request passwords via email
- Include verifiable contact information
If you receive unexpected hotel-related emails, verify independently by logging directly into your booking account or calling the hotel's main line—not numbers provided in the email.
Protection steps
Enable two-factor authentication on hotel loyalty accounts and email. Use unique, strong passwords for travel bookings. Consider using a password manager to avoid reusing credentials. Monitor bank and credit statements for unauthorized charges.
Hotels should review security protocols and notify affected guests of potential data exposure. Customers should remain vigilant: the more personal the phishing message, the more suspicious it warrants.
A newly launched dark web marketplace is selling digital scans of over 153 million driver's licenses from U.S. and Canadian residents. The FBI's New Orleans field office has opened an investigation into the breach, which appears to originate from a Louisiana-based identity verification company.
Five Venezuelan nationals have pleaded guilty to conducting ATM jackpotting attacks across the United States, using malware to extract cash from automated teller machines.
Hackers infiltrated thousands of Dropbox accounts last month, accessing and downloading user files stored on the cloud platform. The company confirmed the breach in a statement reviewed by Bloomberg News.
Threat actors are leveraging the legitimate Faronics Deploy endpoint-management platform to gain administrative control over targeted computers and install ScreenConnect remote support software.