Booking.com Phishers May Leave You With Reservations
ID: d80221d0-edc3-59b9-b935-55a8d6e81898
STIX ID: report--d80221d0-edc3-59b9-b935-55a8d6e81898
Feed Name: Krebs on Security
KrebsOnSecurity reports a widespread phishing campaign targeting Booking.com partner hotels: attackers obtained partner credentials (often via malware/infostealers), registered hundreds of phishing domains (e.g., guestssecureverification.com), and used compromised accounts or purchased access to send fraudulent payment and verification messages to customers. The article highlights marketplace activity selling hotel accounts, phishing infrastructure, and data sets, Booking.com’s move to enforce 2FA for partners, and the broader risk from services that make large-scale credential-based fraud simple and profitable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
