THE NEWS: Bitdefender Antispam Lab has identified two phishing campaigns targeting hotels and other accommodation providers during the peak travel season, one masquerading as prospective guests and the other spoofing Booking.com notifications.
DETAILS:
- In June, Bitdefender warned about WhatsApp hotel phishing scams that used stolen or compromised booking information to impersonate hotels and trick travelers into making fake payments.
- The first new campaign impersonates prospective guests requesting assistance with reservations and lures hotel staff to malicious websites under the pretext of reviewing payment or identity documents.
- The second campaign imitates Booking.com notifications, aiming to convince hotel employees to open malicious links or install malware.
- These attacks shift focus from guests to hotel employees, exposing accommodation providers to credential theft and operational disruption.
WHY IT MATTERS: By targeting hotel staff rather than guests, the campaigns increase the risk of credential compromise, financial loss, and service interruptions for accommodation operators, prompting the need for stronger employee training, email‑security controls, and verification procedures throughout the busy travel season.
FAQ
What are the two new phishing campaigns that Bitdefender Antispam Lab discovered targeting hotels?
Bitdefender Antispam Lab found one campaign that pretends to be prospective guests asking for reservation help and leads staff to malicious sites to review payment or identity documents, and a second campaign that fakes Booking.com notifications to get hotel employees to click malicious links or install malware.
How did the earlier WhatsApp hotel phishing scams operate, according to Bitdefender’s June warning?
The June warning described scammers using stolen or compromised booking information to pose as hotels in WhatsApp messages, persuading travelers to make fraudulent payments by appearing to be legitimate hotel staff. The scams exploit WhatsApp’s popularity and leverage real booking details to increase credibility.
When are these phishing attacks expected to be most active?
Both campaigns were identified as occurring during the peak travel season, when hotel activity and booking volumes are highest, increasing the risk of successful phishing attempts against accommodation providers. Travel operators and hotel chains are advised to heighten email and messaging security protocols during this period to mitigate potential breaches.
Read Original Article.
















