Phishing Campaign Targets Hotel Booking Accounts Worldwide

Cybersecurity researchers have uncovered a sophisticated phishing campaign exploiting compromised hotel booking accounts to defraud travellers. The operation, active since April 2025, uses stolen credentials from hotel administrators to impersonate legitimate communications and direct customers to fraudulent billing pages. The attack begins with spear-phishing emails targeting hotel staff, leading to the installation of PureRAT malware. Once in control, attackers use compromised accounts to execute banking fraud against guests, resulting in significant financial losses.

Latest mentioned: 11-07
Earliest mentioned: 11-06