Security News

Cybersecurity news aggregator

🎣
MEDIUM Attacks HKCERT

Phishing Alert - Beware of Booking.com Phishing Messages Exploiting Suspected Leaked Booking Data

  • What: HKCERT warns about phishing messages using leaked Booking.com data
  • Impact: Users may receive fake messages containing personal booking details
Read Full Article →

Solutions HKCERT urges the public not to assume that a message is genuine simply because it contains their name, hotel name, booking details, or itinerary information. Any notification involving account issues, payment issues, or abnormal booking activity should always be verified through official channels in order to protect personal and financial security. Security Advice for the Public HKCERT reminds the public to: Carefully verify the sender’s email address and the full website URL, and not rely solely on the displayed name to judge authenticity; If you receive a notification related to booking, payment, or account security, check it directly through the official app or by manually entering the official website address; Never click on links in messages from unknown or unverified sources; Never enter account passwords, credit card details, one-time passwords, or other sensitive information on suspicious websites; If in doubt, verify the matter independently through the official website, app, or publicly available contact details of the hotel; Use strong passwords and enable multi-factor authentication to enhance account protection; Regularly review bank account and credit card transaction records for any unusual activity. If You Have Already Submitted Information, Take the Following Actions Immediately If members of the public suspect that they have entered personal information, account credentials, or credit card details on a suspicious website, they should take the following steps as soon as possible: Immediately stop all contact with the other party and do not provide any further personal, account, or financial information; Change the password of the relevant platform account immediately, as well as the passwords of any other accounts using the same or similar password; Contact the relevant bank or credit card issuer immediately, report the incident, and request appropriate protective measures; Closely monitor bank account and credit card transaction records for any unauthorized transactions; Keep all relevant records, including suspicious emails, message screenshots, URLs, website screenshots, and transaction records, for follow-up or reporting purposes. Businesses or members of the public who wish to report to HKCERT on information security related incidents such as malware, phishing, denial of service attacks, etc. can do so by completing the online form at: https://www.hkcert.org/incident-reporting , or calling the 24-hour hotline at +852 8105 6060. For further enquiries, please contact HKCERT at hkcert@hkcert.org .

Share this article