E-mail attacks on the hotel business

Threat actors are targeting hotel staff with malicious and phishing e-mails

Jun 10, 2024

Since last summer, hotel owners and employees have received malicious emails disguised as ordinary correspondence from guests or Booking.com. These emails aim to steal login credentials or infect hotel systems with malware.

Key takeaways

  • Generally, the correspondence follows one of two topics: complaints, or inquiries to clarify some details;
  • In some cases, attackers adopt methods more common to targeted attacks — no malicious link is sent in the first or even the second e-mail. To lull the victim’s vigilance, they initiate a conversation with one or more short, seemingly innocuous messages, asking questions about accommodation conditions at the hotel;
  • By and large, the cybercriminals’ objective in all these cases is to obtain credentials. These can then be used in other scams or simply sold, as databases of such usernames and passwords are in high demand on the dark web.

Get the full story at Kaspersky

Related must-reads

JOIN 34,000+ HOTELIERS

Get our Daily Brief in your inbox

Consumers are changing the face of hospitality - from online shopping to personalized guest journeys and digitalized guest experiences ...
we've got you covered.

By submitting this form, you agree to receive email communication from Hospitality.today and its partners.