< Back to all clusters
[TECHNOLOGY] · Germany · 2 sources

started · updated

Cyberattacks target tourism industry through loyalty fraud and phishing

The tourism industry is facing increasing cyberattacks, specifically through loyalty fraud and sophisticated phishing campaigns. Cybersecurity expert Patrick Coulomb notes that artificial intelligence is acting as an “accelerator,” allowing criminals to generate industrial-scale attacks in seconds.

One prominent method is loyalty fraud, where attackers steal bonus points or flight miles from large accounts to redeem them for free travel. Additionally, AI-generated phishing emails that mimic official airline or travel agency communications are being used to facilitate credit card fraud. In Germany, travel organizers reported preventing an average of 74 fraud cases per month in June and July, representing a potential monthly loss of approximately 113,000 euros.

Separately, Bitdefender has identified a phishing campaign targeting hotel operators via Booking.com. Using the “ClickFix” technique, attackers impersonate guests or official platform messages to trick employees into executing malicious PowerShell commands via the Windows “Run” dialog. This method bypasses traditional security measures by tricking users into manually performing actions that install malware from external servers.

Entities

Bitdefender · Booking.com · Patrick Coulomb