The most alarming aspect of this scam, which has already affected travelers with reservations in key tourist destinations like Maspalomas, is that the cybercriminals handle real details of accommodations with absolute precision, achieving a level of credibility that is very difficult to detect at first glance.
The fraudulent messages arrive directly on customers' mobile phones, impersonating the reception or reservations department of the hotel where the user plans to stay. What dispels the victims' suspicions is the inclusion of specific and reliable data, presumably extracted from previous leaks or security breaches: the exact name of the hotel, the precise check-in and check-out dates, the guest's full name, and even the booking reference number.
Under the urgent pretext of needing to validate, confirm, or resolve an administrative issue with the stay, scammers urge the victim to click on a web link. This hyperlink immediately redirects to a fake payment gateway or website that perfectly mimics the visual identity of the accommodation or online booking platform used. Once on the fraudulent page, the customer is asked to enter sensitive personal data and banking credentials under the guise of reconfirming the reservation, at which point the financial fraud and identity theft are completed.
YURENA VEGA