In-app Phishing Scams : How They Work and How to Avoid Them 

As the number of online bookings increases every year, the travel industry in Spain has become a prime target for cybercriminals.

Phishing scams have become increasingly sophisticated, and in-app phishing scams are a growing trend in the industry.

According to the data from Statista, more than 38 percent of hotel overnight bookings in Spain were made via an online booking agency (OTA) such as This means that out of the 340 million overnight stays by tourists in Spain, about 129 million were booked through a platform such as, one of the leading online travel agencies, is reporting a significant increase in these scams.  

Regrettably, the situation surrounding is not a typical scam. The widely-used travel and hotel website has recently faced numerous complaints regarding in-app fraud and scams.  

One of the most common in-app phishing scams on involves a fake message about an issue with your account.

In-app phishing scams on typically work in one of two ways.

  • Either you’ll receive a message within the app that appears to be from
  • Or you’ll receive an email that claims to be from the company.

These messages will frequently urge you to click on a link or provide personal information such as your email address, password or credit card information.   

The message will claim that there’s been an error with your account or that there’s been suspicious activity in your payment details.

The sender will then ask you to click on a link to resolve the issue. Once you click on the link, you’ll be taken to a fake site that looks like the legitimate site.

The criminals behind the scam will then ask you to enter your account details or payment information, which they will then use to steal your money or identity. 

Once you provide this information, the scammers can then access your account and make fraudulent bookings or steal your personal information. 

In some cases, the phishing messages will also include a fake “urgent” or “limited time offer” to entice users to act quickly without thinking twice.

Beware :These tactics often work on unsuspecting customers who are eager to save money on their bookings.

So, how can you avoid falling victim to these in-app phishing scams?

Here are a few tips: 

  • Always be cautious of any unexpected messages asking for personal information or urgent actions.
  • Double-check the sender’s email address and the link within the message. If it looks suspicious, it probably is.
  • Don’t click on any links or attachments from unknown sources.
  • Use a unique and strong password for your accounts, and never share it with anyone.
  • Enable two-factor authentication whenever possible to add an extra layer of security to your account. 

As customers, we also have a responsibility to report any suspicious activity or messages in the app.

A Comprehensive Guide to Reporting phishing Scams on

To report scams on, both via the app and the website, follow this simple process.

First, it's crucial not to interact with the suspicious activity; don't click any links or provide personal details.

Then, inside the app or on the website, navigate to the 'Contact Us' or 'Help' section.

Here, you'll find options to report suspicious activity or scams. Provide a detailed description of the issue, and if possible, include screenshots as evidence. also recommends forwarding any suspicious emails to Your prompt reporting can help safeguard both your account and the broader user community.

Protecting the Hospitality Industry: A Growing Concern in the Face of Sophisticated Scams

Recognizing that major platforms like have robust security measures in place, hackers have shifted their attention to smaller establishments that may not possess the same level of protection. Exploiting vulnerabilities, these perpetrators patiently monitor transactions, waiting for the opportune moment to strike.

In many cases, the compromised smaller hospitality firms remain unaware of the breach until alerted by their guests. This exemplifies the cunning tactics employed by hackers who strategically target weaker security points.

The implications of such attacks are far-reaching, not only compromising the privacy and safety of guests but also tarnishing the reputation of the affected establishments.

As a unified industry, it is crucial for hospitality providers to remain vigilant and implement robust security measures to safeguard their guests and preserve their own integrity.

By following the steps we’ve outlined, you can protect yourself from these scams and ensure that your personal information and money stay safe.

Always remember to be wary of unexpected messages, and to never click on links unless you’re sure of their authenticity.

By doing so, you can enjoy the convenience of booking trips online without succumbing to phishing scams. 

If your a hospitality provider who is concerned about the rise of in app phishing scams, and how it could effect your business, don't hesitate to contact us today to secure your business environments.

Speedster IT: Your Ally in Hospitality IT Security

We can help hospitality business with

  1. Implementation of robust security measures.
  2. Regular monitoring and maintenance of systems to detect any vulnerabilities.
  3. Providing staff training on recognizing and avoiding potential scams.
  4. Conducting regular audits to ensure the safety of guest data.
  5. Responding promptly to any reports of suspicious activity or phishing scams from both customers and employees.
  6. We are WatchGuard Gold Partners
  7. We are specialists in Hospitality Network security

Don't wait until it's too late, secure your business now with Speedster IT and protect your customers and your reputation.

Stay safe, and happy travels! Speedster IT – Your trusted partner in cyber security.

Protect Your Business Today