Today > vulnerabilities   -   You can now download lists of IOCs here!

Booking.com Phishers May Leave You With Reservations

Nov. 4, 2024, 11:31 a.m.

Description

A recent spear-phishing campaign targeted a California hotel after its Booking.com credentials were stolen. The scam involved sending targeted messages within the Booking mobile app, claiming additional information was required for anti-fraud purposes. Booking.com confirmed a security incident affecting one of its partners, allowing unauthorized access to customer booking information. The company now requires two-factor authentication for partners, but it's unclear if this is enforced for all accounts. Cybercriminals are increasingly targeting Booking.com hospitality partners, with attacks rising 900% in 2024. The article also explores various cybercrime services aimed at phishers targeting hotels that use Booking.com, including the sale of compromised accounts and tools for automated login attempts.

Date

Published: Nov. 2, 2024, 11:40 p.m.

Created: Nov. 2, 2024, 11:40 p.m.

Modified: Nov. 4, 2024, 11:31 a.m.

Attack Patterns

T1586

T1528

T1584

T1566

T1078

Additional Informations

Hospitality

Travel

United States of America