Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

“We cannot say that any of the fraudulent messages we saw were caused by tampering with the hotel’s internal systems,” the researcher said. Fraudulent messages could have been sent using information from other data errors or systems unrelated to travel companies. “What’s more common is that criminals use real-time storage devices and push travelers to get false confirmations or payments,” Corrons says.
Corrons says Norton has not been able to determine who may be behind the attacks but says the investigation is ongoing. Those who send some of the phishing messages seem to be using phishing tools designed to speed up the process of sending and collecting information, he says, and often similar tools or technology have been used. The company doesn’t publish a complete list of potentially disruptive hotels and accommodations, Corrons says; however, it is said that the company has been in contact with Europol regarding its results.
A spokesman for Europol declined to comment, saying it does not discuss its work.
“We continue to strengthen our security to reduce risk and reduce opportunities for bad actors to target our guests and customers, and we are seeing results,” said Booking.com.
Cloudbeds says the company has never been breached and that the attacks described by the Norton researchers targeted hotel staff and then customers. “The reason this scam is so effective is that the attacker has no idea: They know exactly who the visitor is, when they arrived, and what they paid for,” Aaron Ownbey, vice president of engineering at Cloudbeds, says.
Attempts to hack hotels and use customer information to launch fraud attacks have been around for years. In the travel industry, hotels often use different loyalty programs or systems that allow people to make reservations through other companies. At the same time, staff can easily manage customer information and reservations. “Hospitality companies need to put together a security foundation – better training for front desk staff, adopting fraud-resistant authentication, and deeper control over how guest data can be accessed and sent from each platform,” says Ownbey.
Small hotels do not have good security measures, such as multi-factor authentication for employees, says Don Smith, vice president of threat research at the security company Sophos, which has worked with travel companies.
For example, in one event hosted by SophosA cybercriminal recently emailed a hotel that he had lost his passport. In the next message, the attacker included a link to a passport photo; However, when you click on it, the file download includes Vidar info stealerwhich can collect login information from an infected computer. A few days after the malware was deployed, fraudulent messages were sent to customers from Booking.com hotel accounts and people were complaining about losing money.
“Scare players love stories because the story makes the lure of the trick more compelling,” says Smith. “It’s hard not to just take action and click on one thing to take the stress out of travel.”
Corrons, from Norton, says that the inclusion of real information in fraudulent messages can make it difficult to determine what is legitimate and what is fraudulent. If in doubt, he says, contact the hotel or vacation rental directly through another contact method. He said: “Even if the content of the message is true, it does not mean that you can believe the message.