{"id":2034,"date":"2013-06-07T13:00:49","date_gmt":"2013-06-07T17:00:49","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=2034"},"modified":"2020-02-26T10:40:00","modified_gmt":"2020-02-26T15:40:00","slug":"safe-vacation-booking","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/safe-vacation-booking\/2034\/","title":{"rendered":"Stay Safe When Arranging Your Vacation"},"content":{"rendered":"<p>The Internet has revolutionized the way we book our holidays. Unfortunately it is also enabling fraudsters to prey upon people\u2019s desires to have a perfect vacation, so stay vigilant and check everything before spending any money on airline tickets or accommodations.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2013\/06\/06050614\/safebooking_title.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-2035\" alt=\"safebooking_title\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2013\/06\/06050614\/safebooking_title.jpg\" width=\"640\" height=\"420\"><\/a><\/p>\n<p>Nowadays, it\u2019s common for cybercriminals to send out mass amounts of fake emails that are cleverly disguised as legitimate messages. These are generally fraudulant airlines or other travel-associated organizations, such as agencies, hotels and travel agents. This is part of a larger \u201cmalicious traveler\u201d campaign that occurs during popular business and consumer travel seasons.<\/p>\n<p>Scammers usually try to do one of the following:<\/p>\n<ol>\n<li>Steal money, by making you pay for impressively cheap tickets or luxury villas that doesn\u2019t exist or won\u2019t be booked for you<\/li>\n<li>Steal frequent flyer miles<\/li>\n<li>Install a Trojan on your computer to steal banking information and other kinds of valuable data<\/li>\n<\/ol>\n<p>The first kind of scam became particularly easy to implement thanks to the Internet. It\u2019s quite easy to set up a fake website for a travel agency or make a clone of a popular website like booking.com. It looks exactly like any other online service designed to help a traveler; the only difference is that payment goes to scammers instead of hotels or airlines. You will receive an electronic confirmation, but it is impossible to use it when you begin your vacation. According to an ABTA (UK Travel Association) <a href=\"http:\/\/abta.com\/news-and-views\/press-zone\/abta-get-safe-online-and-action-fraud-warn-holidaymakers-look-before-you-bo\" target=\"_blank\" rel=\"noopener nofollow\">study<\/a>, the most dangerous bookings are airline tickets, villas and apartments and packaged trips, especially related to sports or religion. All of them have something in common \u2013 you typically pay in advance.<\/p>\n<div class=\"pullquote\">A large \u201cmalicious traveler\u201d campaign occurs during popular business and consumer travel seasons.<\/div>\n<p>To steal frequent flyer miles, fraudsters send huge amounts of phishing emails that promise more points in a frequent flyer program or offer a supposed prize to victims. In some attacks the customer is asked to re-register on a fake website, which gives cybercriminals the victim\u2019s account information so they can take their miles. By scamming the customer, criminals are able to steal the flyer miles to use as tickets themselves, or sell\/barter them off to other criminals. We saw this in Latin America with airlines in the region and fake American Airlines notifications were also reported in the US.<br>\n<a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2013\/06\/06050611\/fake-booking.png\"><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2013\/06\/06050611\/fake-booking.png\" alt=\"fake-booking\" width=\"640\" class=\"aligncenter size-full wp-image-2037\"><\/a><br>\nOf course, it is easier to trick users into clicking on malicious links when a victim is searching for vacation options. That\u2019s why phishing emails disguised as confirmation emails (like a fake confirmation from US Airways or British Airways). If a user is fooled into clicking on the link, the URL redirects the user to a malicious site that installs a banking Trojan, which infects the computer and steals banking passwords, logins\/credentials. These types of emails can also contain ZIP file attachments asking you to open it to view your confirmation.<\/p>\n<p><b>Booking your vacation in a safe way<\/b><\/p>\n<ul>\n<li>Stick to popular and well-known websites. Don\u2019t visit them using any links inside e-mails or advertising banners. Type the URL in the address bar of your browser \u2013 this helps to avoid clones.<\/li>\n<li>If you\u2019re tempted with an offer from an unknown company, perform some research online. Google the company\u2019s name, visit your country\u2019s tourism authority like the aforementioned ABTA to check the company\u2019s reputation and check that contact details are fully accessible, including a physical address.<\/li>\n<li>Carefully read the terms and conditions to be fully aware of protocol.<\/li>\n<li>Use protected payment, if available \u2013 a credit card, a payment card with traveler\u2019s insurance and so on.<\/li>\n<li>Don\u2019t make a direct payment to property owners, especially through a bank transfer. Use reputable travel agents for apartment\/villa accommodations.<\/li>\n<li>Double-check confirmations you\u2019ve received. If it confirms something you haven\u2019t booked, it\u2019s probably phishing. Brand names of popular sites are often used to produce fraudulent spam by cybercriminals and we advise users to avoid opening the email or clicking any links inside them. If you have a confirmation for a transfer or accommodation you\u2019ve previously booked, use airline or hotel websites\u00a0to ensure its validity. Don\u2019t click links in your confirmation\u2013 type the website name into the address bar of your browser.<\/li>\n<li>Additionally, do not open any email attachments sent from travel agencies, hotels or airlines. Reputable companies will not send confirmations in an attachment.\u00a0 If you doubt the authenticity of an email, you can always contact the company involved using the contact details provided on their official site.<\/li>\n<li>If you have frequent flyer miles accumulated for an airline, stay alert and don\u2019t react to any suspicious messages you may receive by email. Instead of checking your account within the email, type out the URL of the airline\u2019s designated homepage and login directly, as opposed to clicking on links from third parties. \u00a0From there, check your account for any notifications that match the one sent in the email to verify if it\u2019s legitimate.<\/li>\n<li>Protect your logins to airline or travel agency websites with a unique, complex password\/passphrase that you maintain privately and securely.<\/li>\n<li>Use <a href=\"https:\/\/www.kaspersky.com\/pure\" target=\"_blank\" rel=\"noopener nofollow\">total protection of your computer<\/a> to avoid malicious sites and attachments.<\/li>\n<\/ul>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Internet has revolutionized the way we book our holidays. Unfortunately it is also enabling fraudsters to prey upon people\u2019s desires to have a perfect vacation, so stay vigilant and<\/p>\n","protected":false},"author":99,"featured_media":2036,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[189,363],"class_list":{"0":"post-2034","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tips","8":"tag-data-security","9":"tag-personal-data"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/safe-vacation-booking\/2034\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/safe-vacation-booking\/2034\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/safe-vacation-booking\/2034\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/safe-vacation-booking\/2034\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/safe-vacation-booking\/2034\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/safe-vacation-booking\/947\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/safe-vacation-booking\/2034\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/safe-vacation-booking\/2034\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/data-security\/","name":"data security"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/2034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/99"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=2034"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/2034\/revisions"}],"predecessor-version":[{"id":32796,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/2034\/revisions\/32796"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/2036"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=2034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=2034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=2034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}