What is Phishing?
Phishing is a fraudulent attempt, typically made through email, text message, or instant message, to acquire sensitive information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity. Attackers use deceptive messages designed to look like they are from legitimate companies, such as OTAs, banks, or software providers.
These communications often create a sense of urgency or fear, compelling the recipient to click a malicious link or open a harmful attachment. The ultimate goal is to steal data, which can then be used for identity theft, financial fraud, or unauthorized access to accounts.
Join the Lodgify newsletter
How it works
A phishing attack begins when a perpetrator sends a fraudulent message that appears to be from a reputable source. For a property manager, this could be an email that looks like it's from Airbnb, Booking.com, or their payment processor.
The message typically contains a call to action, such as verifying an account, confirming a booking, or updating payment information.
This message includes a link that directs the victim to a counterfeit website, which is a convincing replica of the legitimate site. Unaware of the deception, the host enters their login credentials or financial details.
The attacker captures this information in real-time, gaining access to the host's accounts.
Why it matters
For vacation rental professionals, phishing poses a significant threat. A successful attack can lead to compromised OTA accounts, allowing criminals to defraud guests, alter listings, or divert payouts.
Attackers could also gain access to a property management system, exposing sensitive guest data and operational information. This can result in direct financial loss, severe reputational damage, and potential legal liability for data breaches.
For more information, read about how to protect your business from scams.
Examples
- An email impersonating Vrbo warns a host that their account will be suspended unless they immediately click a link to 'verify their identity,' leading to a fake login page.
- A text message (smishing) claims to be from a guest with an urgent payment issue, providing a link that directs the host to a malicious website designed to steal their credentials.
- A fraudulent email appearing to be from a payment gateway like Stripe or PayPal asks the host to update their banking details to continue receiving payouts.
- An email that looks like an alert from a channel manager software announces a 'mandatory security update' that requires the user to log in via a provided link.
Frequently asked questions
How can I spot a phishing email?+
What should I do if I think my account has been compromised by phishing?+
Are phishing attacks common in the vacation rental industry?+
Related terms
PCI DSS Compliance
PCI DSS Compliance refers to adherence to the Payment Card Industry Data Security Standard, a set of security rules designed to protect cardholder data and…
Two-Factor Authentication (2FA)
Two-factor authentication (2FA) is a security process that requires users to provide two different authentication factors to verify their identity, adding a…
Property Management System (PMS)
A Property Management System (PMS) is a software application that enables vacation rental owners and managers to centralize and automate their core business…
Agentic AI
Agentic AI refers to artificial intelligence systems designed to understand a high-level goal, autonomously create and execute a plan, and use various tools to…
