
Cybercriminals are increasingly attacking both sides of the hospitality industry. In June, Bitdefender warned about WhatsApp hotel phishing scams targeting travelers, with criminals using stolen or compromised booking information to impersonate hotels and trick guests into making fake payments.
Now, Bitdefender Antispam Lab is seeing new waves of attacks aimed at accommodation providers themselves. Instead of targeting guests, these campaigns impersonate prospective customers and Booking.com notifications to trick hotel employees into opening malicious links or installing malware.
The first campaign impersonates prospective guests looking to book a room.
The email appears perfectly ordinary. A supposed traveler claims they are unable to complete a reservation on the hotel's website and politely asks staff to finalize the booking manually. According to Bitdefender Antispam researcher Viorel Zavoiu, the campaign primarily targets hotels and other accommodation providers in the UK, followed by Vietnam, Italy, Ireland, and the United States.
One example observed by Bitdefender reads:
“Hello Reservations Team,
My name is [redacted], and I'd like to book a standard double room for two adults for any two consecutive nights in August after the 10th, subject to your availability.
Unfortunately, I encounter an error each time I try to finalize the reservation on your website. Could you please assist me in securing the room manually?
I have already provided my credit-card details for the deposit and uploaded a scanned copy of my ID. You can view it here...”

Instead of attaching documents, however, the sender includes a link to an external website that supposedly contains their identification and payment details.
The objective is to persuade hotel staff to leave their normal reservation workflow and open a malicious webpage. Depending on the attack, the website may try to steal login credentials, deliver malware, or both.
Although the email looks professional, there are several warning signs:
The second campaign is even more dangerous.
Instead of posing as a traveler, attackers impersonate Booking.com using emails that closely resemble legitimate guest notifications. Based on Bitdefender telemetry, the largest number of targeted businesses were located in Switzerland and the UK.
The messages claim that guests have contacted the property and encourage hotel employees to click a button to read or respond.
Common subject lines observed include:
The emails themselves look entirely routine.
Canceled reservation
Good day, I canceled my reservation and would like to confirm that everything is processed correctly.
Invoice request
Hello, I would like to request an invoice for my stay. Could you please send it after checkout? Thank you.
Follow-up message
Hello, I sent a few messages earlier but didn't hear back. Please respond when possible.
Attackers also impersonate guests asking perfectly reasonable questions about special accommodations.
Traveling with an elderly parent
“We travel with older parent, she can't carry luggage... is help possible?”

or
We will arrive with my elderly mom, she walk slow... can you confirm help pls?

Severe food allergy
I have strong allergy (nuts + sesame), dangerous... can kitchen handle it?

Gluten intolerance
I have gluten intolerance, just want confirm options pls.

Cleaning chemical allergy
One guest have allergy to cleaning chemicals, last time was problem... hope possible fix this?

These requests are designed to lower suspicion because hotels regularly receive questions about accessibility, dietary requirements, allergies, invoices, and cancellations. Additionally, some fake notifications contain basic inconsistencies, including impossible reservation dates in which the listed checkout date comes before check-in. These mistakes may be easy to miss when staff are busy, but they can help expose a fraudulent message.
According to Bitdefender researchers, the attack chain works like this:
This technique is known as ClickFix. Instead of exploiting software vulnerabilities, it tricks people into infecting their own computers by following fake verification instructions.
A malware infection can spread far beyond a single computer.
ClickFix attacks are commonly used to deliver information stealers, remote access trojans (RATs), and malware that downloads additional malicious software.
For hotels and other accommodation providers, that can lead to serious business disruption. Once attackers gain a foothold inside the network, they may be able to:
A single employee clicking one malicious email can quickly become a business-wide security incident, potentially disrupting operations, exposing guest information, and leading to financial losses.
A combination of employee awareness and layered protection can significantly reduce the risk of phishing and malware attacks.
Reservation teams, front-desk employees, and managers should know that cybercriminals increasingly disguise malware as routine communications from guests. Encourage employees to slow down before clicking links, verify unusual requests through the official Booking.com Extranet or other reservation platforms, and remember that legitimate websites never ask them to press Windows + R, paste commands into the Run dialog, or execute PowerShell commands to verify their identity.
Additionally, staff handling guest correspondence or booking platforms should carefully review the mentioned booking dates for inconsistencies (such as a checkout date that comes before check-in), as this may indicate that your property is targeted by cybercriminals.
Regular cybersecurity awareness training is equally important. Employees should know how to recognize phishing emails, suspicious links, and social engineering tactics before they become security incidents. We recently explored this topic in How Employees Can Get Your Small Business Hacked, highlighting how a single mistake can put an entire business at risk.
Technology is the second layer of defense.
Bitdefender Ultimate Small Business Security is designed for small businesses, including hotels, guesthouses, vacation rentals, restaurants, and other hospitality businesses that may not have dedicated IT staff.
It helps businesses:
For very small hotels and accommodation providers, this means spending less time managing security and more time focusing on guests.
Note: This article is published for informational and educational purposes only. The section titled “[Recommended Solution]” contains promotional content about Bitdefender products. The information presented is based on technical research conducted by Bitdefender Labs and publicly available sources. Bitdefender does not make any legal determination regarding the activities described herein. The mention of any company, brand, domain, or individual does not constitute an accusation of illegal activity. Booking.com® is a registered trademark of Booking.com B.V. Readers should exercise their own judgment and consult appropriate authorities or legal counsel if they believe they have been affected by any of the activities described. Domain names and URLs listed in this article are provided solely to help consumers and security professionals identify potentially harmful infrastructure. Bitdefender disclaims any liability for actions taken based on the information in this article.
tags
Alina is a history buff passionate about cybersecurity and anything sci-fi, advocating Bitdefender technologies and solutions. She spends most of her time between her two feline friends and traveling.
View all posts