Monday, November 18, 2024
HomeCyber Security NewsHotel's Booking.com Hacked Logins Let Attacker Steal Guest Credit Cards

Hotel’s Booking.com Hacked Logins Let Attacker Steal Guest Credit Cards

Published on

According to a recent report by Secureworks, a well-planned and advanced phishing attack was carried out, specifically targeting hotels and their guests, through the popular website Booking.com.

The attackers utilized a sophisticated phishing campaign to lure unsuspecting victims into providing their personal information, including payment card data.

The attack highlights the growing threat of cybercrime in the hospitality industry and the need for stronger security measures to safeguard sensitive customer data.

- Advertisement - SIEM as a Service
Document
Protect Your Storage With SafeGuard

Is Your Storage & Backup Systems Fully Protected? – Watch 40-second Tour of SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

Vidar Infostealer Deployed to Steal Credentials

The attackers employed the Vidar info stealer to pilfer Booking.com credentials from hotel staff, showcasing a growing demand for such data on underground forums.

Spearphishing email socially engineering a hotel employee. (Source: Secureworks)
Spearphishing email socially engineering a hotel employee. (Source: Secureworks)

The phishing emails, posing as former guests, strategically deceived employees, leading them to click a Google Drive link containing malware. 

Once credentials were compromised, the attackers exploited the hotel’s Booking.com portal to directly target guests, posing as official communication to defraud unsuspecting victims.

Message used to defraud hotel customers in August 2023. (Source: Secureworks)
The message was used to defraud hotel customers in August 2023. (Source: Secureworks)

The prevalence of Booking.com credentials on underground forums underscores the thriving market for such data, amplifying the frequency and impact of these attacks. 

Recommendations for Organizations and Customers

Secureworks recommends organizations educate employees to identify and thwart phishing attempts, implement multi-factor authentication for Booking.com accounts, and scrutinize access controls. 

Customers are advised to verify requests for payment details, especially through emails or app messages, and report suspicious activity promptly.

Organizations and individuals should remain vigilant to mitigate the risk, understanding evolving cyber threats and implementing appropriate security measures.

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Zohocorp ManageEngine ADAudit Plus SQL Injection Vulnerability

Zohocorp, the company behind ManageEngine, has released a security update addressing a critical SQL...

Citrix Virtual Apps & Desktops Zero-Day Vulnerability Exploited in the Wild

A critical new vulnerability has been discovered in Citrix’s Virtual Apps and Desktops solution,...

Sonatype Nexus Repository Manager Hit by RCE & XSS Vulnerability

Sonatype, the company behind the popular Nexus Repository Manager, has issued security advisories addressing...

GeoVision 0-Day Vulnerability Exploited in the Wild

Cybersecurity researchers have detected the active exploitation of a zero-day vulnerability in GeoVision devices,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Zohocorp ManageEngine ADAudit Plus SQL Injection Vulnerability

Zohocorp, the company behind ManageEngine, has released a security update addressing a critical SQL...

Citrix Virtual Apps & Desktops Zero-Day Vulnerability Exploited in the Wild

A critical new vulnerability has been discovered in Citrix’s Virtual Apps and Desktops solution,...

Sonatype Nexus Repository Manager Hit by RCE & XSS Vulnerability

Sonatype, the company behind the popular Nexus Repository Manager, has issued security advisories addressing...