Hotel Scams Use Real Booking Data for Spear-Phishing Attacks
TL;DR. Scammers exploit stolen hotel reservation data to launch highly targeted spear-phishing campaigns against travelers. - Over 350 hotels globally may have compromised customer data, according to Norton researchers. - Phishing messages contain legitimate booking details to trick victims into sharing credit card information. - Cybercriminals continually develop "phishing-as-a-service" tools, adding new lures to their scams.
- Security researchers from Norton detected reservation hijacking scams affecting over 350 hotels across 50 countries.
- Stolen customer data, including booking names and reservation details, is used to craft highly realistic spear-phishing messages designed to steal credit card information.
- Phishing websites analyzed by Norton included authentic hotel names and specific victim booking details.
- The scams leverage "phishing-as-a-service" software, which is constantly updated with new techniques.
- Germany, France, UK, Italy, Spain, and the US are among the countries most affected by these hotel data compromises.