logo

Hackers Hijack Hotel Booking Workflows to Scam Guests With Fake Payment Requests

ID: 0bf2666c-78da-5b06-a944-2987f8bc9833

STIX ID: report--0bf2666c-78da-5b06-a944-2987f8bc9833

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Gen Digital researchers uncovered a global "Reservation Hijack Scam" where attackers leverage stolen reservation data and compromised hotel management platforms (e.g., Cloudbeds) to send believable payment verification requests via WhatsApp, SMS, email, or booking-platform messaging. Attackers phish hotel staff for credentials, sometimes deploy a remote access trojan through malicious update commands, deliver professionally styled PDFs hosted on hijacked partner storage, and redirect victims to typo‑squatted domains to steal card and bank details; travellers and hospitality operators are advised to verify payments directly, enable multi-factor authentication, and harden messaging/workflow security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.