Hospitality industry facing phishing scam surge

The hotel industry, which relies heavily on technology to manage guest services and operations, has become a prime target for cybercriminals. Phishing—where attackers pose as legitimate entities to trick individuals into divulging confidential information—has become the method of choice for these criminals. These attacks aim to steal user credentials and sensitive guest information, such as payment details, potentially leading to significant financial and reputational damage.

Steven Pieterse, CEO at IT and hotel technology specialist firm Metisware, warns that “in the wake of rising cyber-attacks on the hospitality industry, hotel operators and property managers must be on high alert for a surge in phishing scams.”

Criminals use sophisticated techniques, including fake Google ads and counterfeit websites, to trick hotel staff into entering their login details. Once these credentials are compromised, cybercriminals gain access to sensitive guest information, including payment data, booking records, and personal details, putting the hotel and its guests at risk.

“Cybercriminals are targeting large hotel chains and small and medium-sized establishments,” warns Pieterse.  Hoteliers must understand the seriousness of this situation and take the necessary steps to protect themselves, their business, and their guests.

As phishing scams become more sophisticated, hoteliers must stay ahead of the curve by implementing stringent security measures. Metisware urges all hoteliers to implement the following precautionary steps to safeguard their systems:

  1. Change passwords regularly

This may sound like a stuck record, but hoteliers should ensure that all user passwords are updated frequently. The bottom line is, regular password changes will reduce the chances of unauthorised access.

Passwords must be complex, incorporating a combination of letters, numbers, and special characters. Reusing passwords across different sites should be strictly avoided. Additionally, passwords should never be written down or shared with colleagues.

  “Although it may seem a tedious task, the importance of password management cannot be overstated,” says Pieterse. “A weak or reused password is often the weakest link in a hotel’s security chain. Implement and enforce strong password policies to significantly reduce the risk of credential theft.”

2. Beware of fake login pages and URL scams 

Cybercriminals are increasingly placing fake Google ads that direct users to counterfeit login pages. Clicking on these fraudulent ads can lead staff members to fake websites where their login details are stolen.

Hoteliers are strongly advised not to use search engines to locate login pages. Instead, they should bookmark official URLs to ensure they only access legitimate websites.

Another tactic involves criminals making subtle changes to the URL, tricking users into thinking the site is legitimate. These minor alterations can easily go unnoticed, increasing the risk of users being misled and falling victim to the scam.

3. Be wary of suspicious emails 

Cybercriminals frequently use email phishing schemes to gain access to systems. Hoteliers should train staff to be vigilant when opening emails, especially those containing attachments or links. Verifying the sender’s email address and contacting them directly if there are any doubts is a critical step in preventing phishing attacks.

4. Monitor outbound email activity

 Unauthorised reservation confirmation emails sent from the hotel’s PMS can be a sign of a phishing attack. Hoteliers should regularly monitor outbound emails for suspicious activity. If unscheduled emails are sent without your knowledge, it is crucial to alert the security team immediately.

5. Use firewalls and antivirus software

Not only should you be employing reputable firewalls and anti-malware software to detect and prevent malicious activity, but these systems should be updated regularly to keep up with the latest threats. Ensuring that only authorised users have access to the PMS is also a vital measure. Regular audits should be conducted to remove access for staff members who have left the company.

The hospitality industry has already experienced the detrimental effects of cyber-attacks where hackers compromised the personal data of millions of guests, including payment information. The financial and reputational consequences of these breaches are severe, highlighting the importance of immediate action. “We’ve seen time and again that cybercriminals don’t discriminate based on hotel size or location,” says Pieterse. “Whether you’re a boutique hotel or part of a global chain, you’re a target. Being proactive is your best defence.”

xxx

Metisware Cybersecurity Hybrid Event

Metisware is holding a Cybersecurity Hybrid Event aimed at raising awareness, fostering collaboration, and sharing best practices in the fight against cyber threats. The event will feature hacking demonstrations and topical discussions led by industry experts. The event is free to all those who register and attendees can join in person or online.

Date: 29 October 2024

Time: 15h00 – 17h00

Location: Online or at Protea Hotel Cape Town Durbanville, 99 Jip de Jager Drive, Vineyards Office Estate, Tyger Valley, 7530

For more information and to register, visit Cybersecurity Event

Share:

More News

Foreign Nationals on Your Team: Employer Toolkit

The questions facing South African hospitality employers around foreign national staff have never been more complex or more urgent. Increased immigration enforcement, proposed legislative changes, and heightened public debate have left many business owners asking the same things: What are my obligations? What has changed? And what do I need

Read More »

South Africa’s Restaurant Industry Cannot Continue to Carry More Costs

by Rosemary Anderson, Board Member FEDHASA Inland The latest Statistics South Africa Food & Beverage Survey (May 2026) paints a concerning picture for one of South Africa’s largest employers. While many may view a decline of only 0.3% in real income as relatively insignificant, those operating restaurants, pubs, coffee shops and food service businesses

Read More »
Concierge

FEDHASA Welcomes the South African Concierge Forum, Extending Formal Representation to Hotel Concierges for the First Time

The Federated Hospitality Association of Southern Africa (FEDHASA) has officially invited the South African Concierge Forum to join the association, marking the first time that hotel concierges will have formal representation within South Africa’s most established hospitality industry body. The invitation was extended by Gustav Pieterse, FEDHASA Inland Chairperson, which

Read More »