Hackers are abusing hotel booking notifications to steal credentials in a new phishing campaign




  • Phishing campaign targets hotel staff using fake Expedia and Cloudbeds login pages
  • Attackers show deep knowledge of hospitality workflows to boost credibility
  • Hospitality businesses are prime targets due to constant handling of sensitive guest data

Hotels, and other similar businesses in the hospitality industry, are being targeted by an advanced, highly convincing, phishing campaign.

The goal of the attacks is to harvest usernames, passwords, and potentially multi-factor authentication tokens (MFA) from two hospitality-centric platforms: Expedia Partner Central, and Cloudbeds.

https://cdn.mos.cms.futurecdn.net/ZYWv8BdY3Ekn6zSroLfkwZ.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img