Technology

What is Phishing?

Updated 2026-07-23

Phishing is a fraudulent attempt, typically made through email, text message, or instant message, to acquire sensitive information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity. Attackers use deceptive messages designed to look like they are from legitimate companies, such as OTAs, banks, or software providers.

These communications often create a sense of urgency or fear, compelling the recipient to click a malicious link or open a harmful attachment. The ultimate goal is to steal data, which can then be used for identity theft, financial fraud, or unauthorized access to accounts.

Join the Lodgify newsletter

Once a month, get free templates, expert tips for hosts, industry news, webinar invitations, and more.

How it works

A phishing attack begins when a perpetrator sends a fraudulent message that appears to be from a reputable source. For a property manager, this could be an email that looks like it's from Airbnb, Booking.com, or their payment processor.

The message typically contains a call to action, such as verifying an account, confirming a booking, or updating payment information.

This message includes a link that directs the victim to a counterfeit website, which is a convincing replica of the legitimate site. Unaware of the deception, the host enters their login credentials or financial details.

The attacker captures this information in real-time, gaining access to the host's accounts.

Why it matters

For vacation rental professionals, phishing poses a significant threat. A successful attack can lead to compromised OTA accounts, allowing criminals to defraud guests, alter listings, or divert payouts.

Attackers could also gain access to a property management system, exposing sensitive guest data and operational information. This can result in direct financial loss, severe reputational damage, and potential legal liability for data breaches.

For more information, read about how to protect your business from scams.

Examples

  • An email impersonating Vrbo warns a host that their account will be suspended unless they immediately click a link to 'verify their identity,' leading to a fake login page.
  • A text message (smishing) claims to be from a guest with an urgent payment issue, providing a link that directs the host to a malicious website designed to steal their credentials.
  • A fraudulent email appearing to be from a payment gateway like Stripe or PayPal asks the host to update their banking details to continue receiving payouts.
  • An email that looks like an alert from a channel manager software announces a 'mandatory security update' that requires the user to log in via a provided link.

Frequently asked questions

How can I spot a phishing email?+
Check the sender's email address for slight misspellings or unusual domains. Hover your mouse over links to see the actual destination URL before clicking. Be suspicious of emails that create a sense of urgency or fear. Poor grammar and spelling are also common red flags. Legitimate companies rarely ask for sensitive information directly via email. When in doubt, navigate directly to the company's website in your browser instead of clicking the link.
What should I do if I think my account has been compromised by phishing?+
Immediately change the password for the compromised account. If you use that same password for other services, change those as well. Enable two-factor authentication wherever possible for an added layer of security. Report the phishing attempt to the company that was being impersonated. You should also report the incident to authorities like the Federal Trade Commission (FTC) to help protect others.
Are phishing attacks common in the vacation rental industry?+
Yes, the vacation rental industry is a prime target for phishing attacks due to the high volume of financial transactions and the valuable personal data involved. Attackers frequently target host accounts on major OTAs like Airbnb and Booking.com to take over listings, steal payout information, and defraud guests. They also target property managers' software accounts to gain wider access to data and financial systems, making vigilance essential for all operators.
Keep reading

Related terms

Stay in the loop

Join the Lodgify newsletter.

Once a month, get free templates, expert tips for hosts, industry news, webinar invitations, and more — straight to your inbox.

One email a month. Unsubscribe anytime.