Hospitalityinside WhatsApp Hotel Scams Target Travelers with Phishing Attacks
Article Content
- •WhatsApp is being used for targeted phishing scams against travelers.
- •Attackers exploit real booking information to create convincing messages.
- •The campaign has been active since March 2026 and spans over 10 countries.
A phishing campaign targeting travelers through WhatsApp has been identified, leveraging real booking information to impersonate hotels and resorts. Researchers at Bitdefender Labs have tracked this operation since March 2026, noting its evolution and localization across multiple countries, including the UK, Germany, and Canada. The attackers use convincing hotel branding and personalized messages to deceive victims into providing payment card details. The campaign has affected travelers in over 10 countries, with at least six active phishing campaigns identified. This operation highlights the increasing value of reservation data to cybercriminals, who exploit data leaks from booking platforms. The ongoing nature of this campaign poses a significant threat to travelers, especially during peak travel seasons. No evidence suggests that the impersonated hotel brands were compromised, indicating a focus on brand impersonation rather than direct attacks on the hotels themselves.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Booking in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…