Hackers abusing Hotel Booking -Messages to steal credentials in a new phishing campaign


  • Phishing -campaign is targeted at hotel staff using Fake Expedia and Cloudbed’s Login -sides
  • Attackers showing deep knowledge of workflows to hospitality to increase credibility
  • Hospitality companies are the main targets due to constant handling of sensitive guest data

Hotels and other similar companies in the hospitality industry are targeted by an advanced, very compelling, phishing campaign.

The goal of the attacks is to harvest usernames, passwords and potentially multi-factor approval Tokens (MFA) from two hospitality-centric platforms: Expedia Partner Central and Cloudbeds.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top