Cyber Attacks

Hackers redirect guests to fake Booking.com to steal cards

0

A new sophisticated phishing campaign was discovered by security researchers that targets hotels, booking sites, and travel agencies, designed to steal the financial data of customers.

The hackers compromise and send phishing messages via the affected service’s official communication channels.

Researchers at Perception Point found that the campaign begins with a seemingly harmless query or reference to an existing hotel reservation. It also uses advanced social engineering techniques and then send allegedly important documents via a URL.

After clicking the URL, the victim is directed to an info-stealing malware. This malicious software is adept at collecting sensitive information, including credentials and financial data.

The final phase of the attack involves the victim receiving a link for alleged credit card verification. This unveils a fake Booking.com payment page – designed to be another method of stealing the user’s financial info.

Researchers from Akamai noted that the attackers gain access to legitimate customer communication channels after infiltrating the hotel’s systems. This provides them with a direct and trusted channel to their victims. Under the guise of the compromised hotel, booking service, or travel agency, the cybercriminals are able to send phishing messages that closely mimic genuine requests.

Users must remain vigilant to protect against such phishing campaigns. Avoid clicking on unsolicited links, even if they seem legitimate, and exercise caution with messages urging immediate action.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Web3 Platform Mixin network hit by $200m crypto hack

Previous article

Xenomorph Malware targets US banks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *