Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Hackers are abusing hotel booking notifications to steal credentials in a new phishing campaign

Tech Wavo by Tech Wavo
September 10, 2025
in Computers
0




  • Phishing campaign targets hotel staff using fake Expedia and Cloudbeds login pages
  • Attackers show deep knowledge of hospitality workflows to boost credibility
  • Hospitality businesses are prime targets due to constant handling of sensitive guest data

Hotels, and other similar businesses in the hospitality industry, are being targeted by an advanced, highly convincing, phishing campaign.

The goal of the attacks is to harvest usernames, passwords, and potentially multi-factor authentication tokens (MFA) from two hospitality-centric platforms: Expedia Partner Central, and Cloudbeds.

This is according to Mimecast’s Threat Research Team, and researchers Samantha Clarke and Ankit Gupta. The team discovered an ongoing campaign distributing “urgent, business-critical subject lines designed to prompt immediate action from hotel managers and staff.”


You may like

Sophisticated understanding of hospitality workflows

Usually, the email messages discuss common tracking alerts, system updates, guest booking confirmations, and partner central notifications. These are regular topics in the hospitality industry, and are generally time-sensitive. Hotels that fail to address these messages on time usually end up losing revenue.

This means that, whoever is behind this campaign, has “sophisticated understanding of hospitality workflows,” the researchers further explained. The links in the emails then redirect the victims towards malicious landing pages, designed to look identical to login pages of Expedia and Cloudbeds.

This is where the attackers capture login credentials and, potentially, 2FA codes. All of the landing pages were hosted on Vercel, they added.

Sensitive data, such as email addresses, Social Security Numbers, passport and government ID numbers, dates of birth, postal addresses, and similar, are quite valuable to cybercriminals.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

They allow them to launch phishing attacks that can give them access to important services, bank accounts, and more. Businesses in the hospitality industry, on the other hand, generate this type of data constantly, making them a prime target for campaigns such as this one.

Less than a month ago, a cybercriminal managed to break into the booking system used by numerous hotels in Italy and steal highly sensitive information on thousands of guests. Before that, high-profile hotel chains, including Marriott and Hilton, all had sensitive customer data leak as part of a supply-chain attack against a partner.

You might also like

Previous Post

Apple isn’t making any carbon neutral claims with its Series 11 smartwatch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Hackers are abusing hotel booking notifications to steal credentials in a new phishing campaign

by Tech Wavo
September 10, 2025
0
Hackers are abusing hotel booking notifications to steal credentials in a new phishing campaign
Computers

Phishing campaign targets hotel staff using fake Expedia and Cloudbeds login pagesAttackers show deep knowledge of hospitality workflows to boost...

Read more

Apple isn’t making any carbon neutral claims with its Series 11 smartwatch

by Tech Wavo
September 10, 2025
0
Apple isn’t making any carbon neutral claims with its Series 11 smartwatch
Computers

Apple hosted its "Awe dropping" today, but wearables also got their moment in the sun, including the announcement of the...

Read more

It’s official, the iPhone 17 will be available to preorder this Friday – here’s what time and the confirmed deals

by Tech Wavo
September 10, 2025
0
It’s official, the iPhone 17 will be available to preorder this Friday – here’s what time and the confirmed deals
Computers

Apple has officially lifted the curtain on the iPhone 17 lineup, with preorders set to begin this Friday, September 12th....

Read more

BMW Deal Sparks Tesla Rivalry in Autonomy

by Tech Wavo
September 10, 2025
0
BMW Deal Sparks Tesla Rivalry in Autonomy
Financial

Shares of Qualcomm Inc. NASDAQ: QCOM closed around $160 on Monday, once again running into resistance at a level they have...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock