- 14 Mar 2002
- 21,050
- 18,903
Since last May, Japan has been plagued by phishing scams targetting Booking.com and other travel sites, affecting at least 68 hotels. The stolen information mainly involved foreign visitors. A security company found Russian hackers behind it: they usually pretended to be travellers or hotel staff. They obtained the hotel IDs and passwords to access Booking.com and then tricked the travellers into entering their credit card information on a fake site.
The email contained a link that, once clicked, triggered a virus infection, allowing the hacker to obtain hotel IDs and passwords when accessing Booking.com fraudulently. The hackers then used these credentials to gain unauthorized access to Booking.com and sent messages to travellers pretending to be hotel staff. The messages falsely claim that "advance payment is required" and then force travellers to enter their credit card numbers and other details into a fake site that resembles Booking.com to steal the information. [...] The company did not reveal the global scale or estimated damages but said some of the 6.6 million facilities that use Booking.com were compromised.