According to a recent report by Secureworks, a well-planned and advanced phishing attack was carried out, specifically targeting hotels and their guests, through the popular website Booking.com.
The attackers utilized a sophisticated phishing campaign to lure unsuspecting victims into providing their personal information, including payment card data.
The attack highlights the growing threat of cybercrime in the hospitality industry and the need for stronger security measures to safeguard sensitive customer data.
StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.
The attackers employed the Vidar info stealer to pilfer Booking.com credentials from hotel staff, showcasing a growing demand for such data on underground forums.
The phishing emails, posing as former guests, strategically deceived employees, leading them to click a Google Drive link containing malware.
Once credentials were compromised, the attackers exploited the hotel’s Booking.com portal to directly target guests, posing as official communication to defraud unsuspecting victims.
The prevalence of Booking.com credentials on underground forums underscores the thriving market for such data, amplifying the frequency and impact of these attacks.
Secureworks recommends organizations educate employees to identify and thwart phishing attempts, implement multi-factor authentication for Booking.com accounts, and scrutinize access controls.
Customers are advised to verify requests for payment details, especially through emails or app messages, and report suspicious activity promptly.
Organizations and individuals should remain vigilant to mitigate the risk, understanding evolving cyber threats and implementing appropriate security measures.
Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.
Zohocorp, the company behind ManageEngine, has released a security update addressing a critical SQL injection…
A critical new vulnerability has been discovered in Citrix’s Virtual Apps and Desktops solution, which…
Sonatype, the company behind the popular Nexus Repository Manager, has issued security advisories addressing two…
Cybersecurity researchers have detected the active exploitation of a zero-day vulnerability in GeoVision devices, which…
A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious actors…
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers…