Hospitalityinside
WhatsApp Hotel Scams Target Travelers with Phishing Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A phishing campaign targeting travelers through WhatsApp has been identified, leveraging real booking information to impersonate hotels and resorts. Researchers at Bitdefender Labs have tracked this operation since March 2026, noting its evolution and localization across multiple countries, including the UK, Germany, and Canada. The attackers use convincing hotel branding and personalized messages to deceive victims into providing payment card details. The campaign has affected travelers in over 10 countries, with at least six active phishing campaigns identified. This operation highlights the increasing value of reservation data to cybercriminals, who exploit data leaks from booking platforms. The ongoing nature of this campaign poses a significant threat to travelers, especially during peak travel seasons. No evidence suggests that the impersonated hotel brands were compromised, indicating a focus on brand impersonation rather than direct attacks on the hotels themselves.
Key Points: • WhatsApp is being used for targeted phishing scams against travelers. • Attackers exploit real booking information to create convincing messages. • The campaign has been active since March 2026 and spans over 10 countries.