Feeds

Phishing scam aims to hoodwink hotel habitants

Counterfeit site ruse proves hard to pin down

Security for virtualized datacentres

Phishing fraudsters have moved on from banking sites with an attack designed to hoodwink hotel customers, according to a team of security volunteers.

Hotel chains including Hyatt, TraveLodge, Comfort Inn, Ramada, Days Inn, and Wyndham are being targeted in the reported scam. More than 71,000 travelers each month have been redirected to counterfeit sites, volunteer security community FraudTip.com warns. Mainstream net security firms are unable to confirm these figures.

FraudTip.com culled its figures using "audience measurement" technology. It reckons the scam combines "advanced online advertising, bogus hotel locators, third-party reservation systems, and Internet browser crimeware to redirect hotel guest traffic to fake versions of well-known hotel chain websites".

However net security firms reckon the attack is nothing more or less than a straightforward phishing scam, albeit one directed at hotels rather than banks or ecommerce outlets. Some element of search engine trickery to inflate the rank of counterfeit sites may also be involved.

Roger Thompson, chief of research at AVG, said the attack described had all the hallmarks of a phishing assault that didn't involve malware.

"For what its worth, there's no mention of those brands in my records," he told El Reg. "I've also not heard of any malware doing any man in the middle attacks like that either. It's certainly possible, but I would think the machine is already hosed if they've got that sort of malware installed."

Symantec said the attack hadn't hit its radar either.

"I have looked through all of our normal sources and also checked to see if any of the hotels mentioned in this report show up in our databases as recently compromised - they haven't," a spokeswoman told us.

Nobody from FraudTip.com was immediately available to discuss details of the hotel chain attacks. ®

Beginner's guide to SSL certificates

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.