216.73.216.36

Booking.com Phishers May Leave You With Reservations

· Published 02/11/2024 23:40 · Modified 04/11/2024 11:31

Export JSON

Essential information

Published
02/11/2024 23:40
Modified
04/11/2024 11:31
Tags
2024-11-02 2fa booking.com credential-theft cybercrime hospitality phishing travel
Related entities
5 techniques (mitre), 3 others

Description

A recent spear- campaign targeted a California hotel after its credentials were stolen. The scam involved sending targeted messages within the Booking mobile app, claiming additional information was required for anti-fraud purposes. confirmed a security incident affecting one of its partners, allowing unauthorized access to customer booking information. The company now requires two-factor authentication for partners, but it's unclear if this is enforced for all accounts. Cybercriminals are increasingly targeting partners, with attacks rising 900% in 2024. The article also explores various services aimed at phishers targeting hotels that use , including the sale of compromised accounts and tools for automated login attempts.

External references