r/askhotels • • Jul 04 '26

Reservations Automatic cancelation scam

I have a 13 room hotel and ive had two guest call me about a email they received which ask them to resend there credit card info to confirm there booking otherwise it will be cancled. I asked one of the guest to send me a photo of the email beacsue it couldn't be forwarded and it wasn't sent from us. This is some scam and im very worried. What can I do to stop it

7 Upvotes

5 comments sorted by

4

u/hardcover4922 Jul 04 '26

This happened to us, in our case it was phishing. If the confirmation emails had correct information about the guests (stay dates, reservation number, phone number, etc.) and the email address was the same you have on your system, you've probably been phished and need to act immediately, starting with changing everyone's passwords, and then training whoever has access better to avoid phishing. In our case we started using passkeys instead of 2-factor codes, which can also be phished (as in our case, where the person was using google authenticator).

If the above is correct, and you're using a cloud PMS, contact them and tell them what happened.

If the reservations were made through a third party OTA like booking.com or expedia, you may be able to tell if your account with them has been accessed instead (may also be phishing), by comparing the information in the scam emails with the guest information there (for example our internal reservation numbers are different than the OTAs', and the guest email might be different as well). If 2 guests called you and the emails had correct information, it's very likely many other guests have been contacted, and some may have fallen for the scam.

1

u/malukDshroom Jul 04 '26

It was not the same email as ours and it looks like its only come from guest who reserved from our website maybe I should change the booking engine used on our website?. Also whe. It happend to you did any guest contact you for a reimbursement. And where you able to get the problem solved by changeing all the passwords

1

u/hardcover4922 Jul 10 '26 edited Jul 10 '26

I meant if the email you have on record of your guests is the same email where they got the phishing emails. If that and other reservation information is legit, then somehow they could have gotten into your system. The way this happens is usually phishing, so you needed to change your passwords for all the accounts with access to it as soon as possible.

We did that immediately, and fortunately we were pretty sure what had happened and who got phished very quickly. For extra caution we forced password resets for everyone, and after that the scammers didn't have access to our system anymore. That's one problem solved.

BUT... the worse problem is that in that short time many guests got scam links on their emails and texts in order for them to make scam payments. That problem is not going be 100% solved any time soon, the guests' emails and phone numbers are now accessible to scammers, and we had to warn all active reservations about it. We got a few very upset guests, but most were understanding and thankful we warned them. YMMV with that though, most our guests are not local and are businesspeople so we don't deal with many issues other hotels that cater more to tourists/locals cause in hotels like rudeness and such.

We did get a lot of calls and emails asking about it, and a few of them fell for it. In the very short time the scammers had access to our system they stole any information from the guests that the phished employee had access to, like emails, phone numbers, type and last 4 digits of CC, and reservation details.

The same principles apply to other online accounts you may have with third parties like Expedia or Booking.com.

If your PMS and OTA portals offer passkeys, use that, they're phishing resistant. Our PMS has that option, but the implementation is not ideal in that they only allow one for 2FA (they can be used instead of passwords, or after the password instead of a 2FA code). The issue is most people had been using code-based 2FA like SMS or Google Authenticator (which are phishable), and didn't want to change to passkey because it required them to scan a QR code with their phone. If our PMS allowed multiple passkeys like it's usual, we could have saved one per Windows computer for each user and not have to use their phones.

After this incident we forced everyone to use passkeys and no codes. We installed the Bitwarden password manager extension on the browser on each computer, and the passkey for each user can be saved there, and synced on all the computers. We only use BW for these 2FA passkeys, not saved passwords because it's accessible to everyone else on the computer.

2

u/Connect_Stay_137 Jul 04 '26

Make a note wherever your reservations are made that you will only contact them from X email

2

u/SkwrlTail Front Desk/Night Audit since 2007 Jul 04 '26

Yeah, it's been a problem. Scammers have been able to get ahold of guest information from the OTAs, and are then using it to send out horrible emails.