Phishing wave in hotel bookings: cybersecurity authority warns of new fraud scheme

Bacs recorded a sharp increase in fraudulent messages based on stolen reservation data in May.

Phishing wave in hotel bookings: cybersecurity authority warns of new fraud scheme

Phishing wave in hotel bookings: cybersecurity authority warns of new fraud scheme

Switzerland's digital security authority reported a significant increase last month in cases where criminals attempt to obtain credit card information from hotel guests via WhatsApp or other channels. In May, 23 reports were received, compared to only eight in April – an increase not recorded in previous years.

The perpetrators are exploiting information that leaked in April in an incident at the booking platform Booking.com. Using these details about past or planned stays, they lend their messages an apparent legitimacy that deceives many recipients.

As Nau.ch reports, the criminals employ two different approaches. In the first variant, they write to guests and claim that an error occurred during a previous reservation and a refund is pending. An attached link first leads to a counterfeit Twint page and then to a fake bank website, where victims are asked to enter card details.

The second variant targets open or upcoming bookings. Here, the senders threaten cancellation unless credit card verification or a deposit is made immediately. Again, a link directs to fraudulent pages that appear authentically convincing.

The cybersecurity authority advises remaining fundamentally sceptical of unsolicited messages – even if senders provide correct reservation details. One should never click on links or enter card data. Instead, direct access via the official app or website of the booking portal is recommended. Anyone who has already disclosed data should have their card blocked and file a criminal complaint.

Country of incident: Switzerland (CH) Suspected perpetrator nationality: xx

Source: Google News CH — Crime (de)

Read this article in the original language