Hackers are abusing hotels notifications to steal credentials in a new Phishing campaign




  • The Phishing campaign is addressed to hotel staff that uses false login pages of Expedia and Cloudbes
  • The attackers show a deep knowledge of hospitality workflows to increase credibility
  • Hospitality companies are main objectives due to the constant management of confidential guests

Hotels and other similar companies in the hospitality industry are being attacked by an advanced, convincing phishing campaign.

The objective of the attacks is to reap usernames, passwords and potentially multifactor (MFA) authentication tokens of two hospitality focused on hospitality: Expedia Partner Central and CloudBeds.

Leave a Comment

Your email address will not be published. Required fields are marked *