Hotel phishing is the most successful attack running against UK hospitality right now, and it does not start in a server room. It starts at a desk in your lobby, or in a back-office reservations inbox, where somebody whose entire job is to be helpful to strangers opens an attachment from a stranger. Every other control you have bought sits behind that moment.

This guide is written for the people who actually get targeted: front desk agents, night auditors, reservations and events coordinators, revenue managers, and the general manager who signs off supplier payments. It sets out the hotel phishing lures that work on hospitality teams specifically, why multi-factor authentication no longer stops the better attacks, and what a UK property can realistically put in place in ninety days.

It sits alongside our wider hotel cyber security checklist and our guide to Microsoft 365 for hotels. Where those cover the whole estate, this one stays on the human edge of it, because that is where hotel phishing is won or lost.

What Hotel Phishing Actually Targets, and Why It Works

hotel phishing attacks front desk reservation teams b upright sealed envelope

Hotel phishing is not a generic spam problem with a hospitality logo on it. It is a targeted pattern that exploits three things almost every hotel has: a published inbox, a rota, and a culture of saying yes.

The front desk is a public inbox with a door key attached

Your reservations address is printed on your website, syndicated to every online travel agent, scraped by aggregators and pasted into thousands of confirmation emails. It is one of the most discoverable email addresses your business owns. Behind it sits an account that can usually read guest records, sometimes reach the property management system, and almost always send mail that looks like the hotel.

That combination is unusual. Most businesses guard their privileged accounts and publicise their marketing ones. A hotel publicises the account that touches guest data every hour of every day, which is exactly why hotel phishing pays.

Hotel phishing now aims at the role, not the person

This is not speculation. In June 2026 Microsoft Threat Intelligence published an analysis of a hospitality campaign it tracks as “Photo ZIP”, active since April 2026 across Europe and Asia, which targeted reception, front desk, reservations and other guest-facing roles. Microsoft’s most telling observation was about the subject lines: “Every subject references an anonymous ‘guest,’ ‘facility,’ or ‘your accommodation,’ and none contains a recipient name.”

That is a campaign engineered for shared role mailboxes. It is designed to land in reservations@ and info@ and be opened by whoever is on shift, which is precisely how a hotel works and precisely why generic advice about “checking whether the email addresses you by name” does not help here.

Reservations staff are paid to open attachments from strangers

In most industries, “do not open unexpected attachments” is workable advice. In a hotel it is nonsense. Reservations teams receive rooming lists, purchase orders, event schedules, dietary requirement sheets, identity documents and signed authorisation forms from people they have never met, all day, and they are measured on how quickly they turn them around.

Any hotel phishing awareness programme that opens with “never open attachments” is dead on arrival. The advice has to be shaped around the job, not against it.

Shift work quietly breaks your escalation path

The third weakness is structural. A finance team works nine to five and can walk to a colleague’s desk. A front desk runs three shifts, seven days, often with one person on at 03:00. The colleague you would normally ask is asleep, and the IT provider’s line goes to an out-of-hours queue. Attackers know this, which is why so much hotel phishing and voice-phishing pressure lands in the evening, overnight, or on a bank holiday weekend.

The Numbers Behind Hotel Phishing in the UK

hotel phishing attacks front desk reservation teams c clipboard with blank sheet

It helps to anchor the discussion before modelling your own property, because hotel phishing is a specific case of a problem that is already the dominant one across British business.

What the national survey says

The Department for Science, Innovation and Technology’s Cyber Security Breaches Survey 2025/2026, published on 30 April 2026 and based on fieldwork with 2,112 UK businesses between August and December 2025, found that 43% of businesses identified a cyber breach or attack in the previous twelve months — roughly 612,000 organisations. Phishing was experienced by 38% of businesses and was rated the most disruptive breach type by 69% of those affected.

Two further figures matter more than the headline. Among businesses that experienced any cyber crime, 93% experienced phishing. And among breached businesses, 51% experienced phishing and nothing else, up from 45% the year before. Phishing is not one risk among many; increasingly it is the whole risk.

UK businesses and phishing — Cyber Security Breaches Survey 2025/2026
Of businesses hit by cyber crime, share that faced phishing 93%
Rated phishing their most disruptive breach 69%
Breached firms that faced phishing and nothing else 51%
Identified any breach or attack 43%
Experienced phishing specifically 38%

The hospitality gap is the number to take to your board

The same survey breaks results down by sector, and the food and hospitality result is stark: only 30% of businesses in that sector treat cyber security as a high priority for senior management, against 72% of UK businesses overall. That single comparison explains most of what follows. Hospitality is not being targeted more heavily than everyone else; it is defending less.

Nationally the picture is thin everywhere. Across all businesses, 47% use two-factor authentication, 25% have a formal incident response plan, and just 19% have run any staff training or awareness sessions in the past year. If your hotel has done all three you are already in a small minority.

What the hospitality-specific hotel phishing data shows

Sector-level intrusion data is scarcer, but Trustwave’s 2025 Risk Radar Report for the hospitality sector puts numbers on initial access: exploitation of public-facing applications accounted for 61.5% of observed initial access attempts, phishing for 23.4%, and use of valid accounts for 15.1%. Read the second and third together — nearly four in ten hospitality intrusions begin with a person or a stolen credential rather than an unpatched server.

Verizon’s 2026 Data Breach Investigations Report, covering 31,861 incidents and 22,625 confirmed breaches, recorded 319 incidents in the accommodation sector with 250 confirmed data disclosures. It found the human element present in 62% of all breaches, social engineering in 16%, and — notably for hotels — that 41% of social engineering breaches arrived by a vector other than email.

The Front Desk and Reservations Inbox as a Hotel Phishing Attack Surface

hotel phishing attacks front desk reservation teams d2 solid speech bubble

Before you can reduce hotel phishing risk you need an honest map of every channel through which a stranger can put a message in front of your staff. It is longer than most managers expect.

Shared mailboxes and shared logins

Almost every hotel runs shared addresses: reservations@, frontdesk@, info@, events@, accounts@. Many run shared logins to match, because it is simpler than licensing eight named users on a rota. That decision quietly destroys three things at once — you lose per-person accountability, you cannot apply per-person conditional access sensibly, and after a hotel phishing incident you cannot tell which of the eight people on the rota clicked.

Our Microsoft 365 setup guide for hotels covers the pattern that fixes this: named accounts for every human, and shared mailboxes with delegated access rather than shared passwords.

The channels nobody counts

Email is the obvious one. It is not the only one. Guests and impostors also reach your team through the travel platform’s in-app messaging, the telephone, WhatsApp and SMS on a duty manager’s mobile, the website contact form, QR codes stuck on tables and lift doors, and physical USB drives handed over at the desk with “the wedding photos, could you print these?”

ChannelWho is exposedWhy it is hard to defendPrimary control
Reservations mailboxReservations, revenueAttachments from strangers are the jobSafe Attachments, detonation, named accounts
Travel platform messagingReservations, front deskArrives inside a trusted systemNever leave the platform to act on a message
Inbound telephoneFront desk, night auditNo headers, no filter, live pressureCallback on a number you already held
WhatsApp and SMSDuty managers, GMPersonal device, no loggingBan approvals over consumer messaging
QR codes on siteGuests, and staff who test themDestination invisible before the scanTamper-evident printing, weekly walk round
Removable media at the deskFront deskHanded over in person by a real guestDevice control policy, blanket refusal

In hotel phishing the account matters more than the mailbox

One correction worth making early: the prize is rarely the mailbox itself. A reservations account often holds the password reset path for the channel manager, the booking engine, the travel platform extranet and sometimes the property management system. Treat every hotel phishing incident as an identity incident rather than an email incident and your response improves immediately.

How a Hotel Phishing Attack Unfolds, Step by Step

hotel phishing attacks front desk reservation teams e2 solid hand bell

Understanding the sequence matters because almost every effective control interrupts one specific step. Teams that only think about “spotting the dodgy email” are defending one link in a chain of five.

Step one: reconnaissance

The attacker reads your website, your travel platform listings and your LinkedIn. Within an hour they know your brand, your reservations address, the names of your general manager and revenue manager, and often which channel manager and PMS you run, because your job adverts say so. Hotels publish more operational detail than almost any other sector.

Step two: the lure

They send something that fits the job. Not a lottery win — a rooming list, an invoice query, a complaint, a booking amendment. The best hotel phishing lures are indistinguishable from Tuesday’s actual workload, which is the entire point.

Step three: credential capture or code execution

One branch goes to a sign-in page that looks exactly like Microsoft 365 or the extranet. Increasingly it is not a static clone but a live proxy that relays real credentials to the real site and steals the resulting session. The other branch skips credentials entirely and persuades the user to run something themselves.

Step four: quiet persistence

Once inside, the attacker rarely announces themselves. They add a forwarding rule, or an inbox rule filing anything containing “invoice” or “bank” into an obscure folder, or they register their own authenticator so the password reset you eventually perform does not evict them. Microsoft’s guidance on the 2026 hospitality campaign is a good illustration of how mundane this is: responders were told to check both the Run and RunOnce registry keys, because clearing only one leaves the implant in place.

Step five: monetisation

Only then does money move: a redirected supplier payment, a fraudulent card harvest from your guests, a sale of the extranet credentials, or ransomware timed for your busiest weekend. Our hotel ransomware continuity guide picks up at exactly this point.

The Hotel Phishing Lures That Work on Reservation Teams

hotel phishing attacks front desk reservation teams f2 reception counter desk

Generic training uses generic examples. It fails in hotels because the examples do not look like the job. Here is the hotel phishing catalogue that actually lands in hospitality inboxes, drawn from campaigns security vendors have documented rather than from imagination.

The booking confirmation or photo attachment

A message appearing to come from a guest or agent, attaching a “confirmation”, “voucher” or set of photographs. The 2026 hospitality campaign Microsoft documented used a photo-[random].zip archive containing a shortcut file disguised as an image, which installed a Node.js implant when opened. Password-protected archives are a common variant, because the password in the email body defeats most attachment scanning.

The guest identity document

“Attached is my passport as requested for check-in.” Hotels genuinely ask for this and UK properties have long-standing obligations to record certain guest details, so the request is entirely plausible. The plausibility is manufactured and the attachment is the payload.

The card verification request

Either direction works. A fake guest asks your team to confirm the card on file by replying with the digits. Or a fake platform notice tells your team the guest’s card failed and directs them to a portal to re-enter it. Both end with card data somewhere it must never be, which we cover in depth in our guide to PCI DSS for hotels.

The complaint that threatens your rating

An angry message about a stay, with evidence attached and a threat to publish. It targets the exact instinct hotel staff are trained to have: fix it fast, before it becomes a one-star review. This is a documented pattern, not a hypothetical — the Knight ransomware operation distributed itself in emails impersonating TripAdvisor complaints, with attachments named to suggest a possible listing suspension. Urgency plus reputational fear is the strongest combination in hotel phishing.

Health, hygiene and inspection scares

The 2026 hospitality campaign ran bedbug infestation reports and facility complaints alongside ordinary guest queries. These work because they are operationally urgent, they are embarrassing, and nobody wants to be the agent who left one sitting in the inbox overnight.

The group booking with a spreadsheet

A conference organiser sends a rooming list as a macro-enabled spreadsheet, then chases for a reply. High value, plausible format, and the follow-up manufactures the deadline pressure.

The internal impersonation

An email appearing to come from the GM or the owner, sent to the duty manager, asking for something slightly unusual and slightly urgent. It works best on a Friday evening.

Hotel phishing lureTarget roleAttacker goalThe tell
Photo or confirmation archiveReservationsImplant executionArchive containing a shortcut, no booking reference
Guest identity documentFront deskMalware executionUnrequested, arrives before any booking exists
Card verification requestReservations, front deskCard data theftAsks for card details by email or linked form
Review or complaint threatDuty manager, GMCredential capture, ransomwareThreat plus deadline, link to “evidence”
Hygiene or inspection scareFront desk, housekeeping leadImplant executionNo room number, no dates, no booking record
Group rooming listEvents, reservationsMacro executionMacro-enabled file from a brand-new contact
GM impersonationDuty manager, financePayment diversionReply-to differs from display name, out of hours
Platform partner alertReservations, revenueExtranet credential theftDirects you out of the platform to sign in

Hotel Phishing That Impersonates Booking Platforms and Channel Managers

The single most effective hotel phishing pattern of recent years impersonates the online travel agent, because it inverts the trust relationship your team relies on.

Why platform impersonation beats ordinary hotel phishing

Your reservations team treats mail from a booking platform as operational instruction, not correspondence. It arrives constantly, it is usually automated, it usually requires an action, and ignoring it has commercial consequences. That is an almost perfect environment for an attacker.

Microsoft Threat Intelligence documented one such campaign in March 2025, attributed to an actor it tracks as Storm-1865, which began in December 2024 and impersonated Booking.com in emails to hospitality organisations across Europe, North America, Oceania and Asia. The lures were negative guest reviews needing a response, enquiries from prospective guests, promotion opportunities and account verification requests.

ClickFix: the trick that turns your own staff into the installer

The delivery method is the part of this hotel phishing pattern worth memorising. Instead of attaching malware, the page shows a fake CAPTCHA and instructs the user to open the Windows Run dialog, paste a command the page has quietly copied to their clipboard, and press enter. Microsoft’s own summary of why it works is blunt: “This need for user interaction could allow an attack to slip through conventional and automated security features.”

That campaign delivered a suite of credential stealers and remote access tools including XWorm, Lumma, VenomRAT, AsyncRAT, DanaBot and NetSupport RAT. Verizon’s 2026 report found ClickFix-style activity in around 2.7% of attacks detected at the browser, and describes users being walked through keyboard shortcuts to paste the payload themselves.

The rule for your team is therefore absolute and needs no technical judgement: any web page that asks you to press a key combination, open a Run box, paste something you did not copy, or run a command is an attack. There is no legitimate version of that request.

When the attacker is inside a genuine platform account

The harder variant does not impersonate the platform at all. In November 2025 the threat research team at Sekoia documented a campaign they named “I paid twice”, running from at least April 2025, in which compromised hotel extranet accounts were used to message guests — over email and WhatsApp, quoting their real reservation details — and walk them to a lookalike page that harvested their banking information.

There is no spoofed domain to detect and no header anomaly to spot, because the message genuinely came from the platform. Sekoia also documented the market underneath it: individual hotel extranet credentials trading from around $5 to as much as $5,000 depending on quality, with premium access to multiple properties in developed countries fetching the top prices. Your reservations login is a listed commodity.

The uncomfortable part: the mail can pass every authentication check

The 2026 hospitality campaign went a step further by routing its phishing through legitimate infrastructure — a scheduling service’s mail sending platform and a well-known URL redirector — with a sender display name crafted to read as a booking manager notification. Microsoft’s assessment is the sentence every hotel IT decision should be built on: routing messages through a trusted service’s sending infrastructure makes them appear similar to legitimate notifications “to email authentication defenses.”

In plain terms, the mail can pass SPF, DKIM and DMARC and still be an attack. Email authentication remains essential, and we cover it below, but it is not a hotel phishing filter.

What a booking platform will never ask you to do

Give your team a short, memorable list. No legitimate travel platform will ask a hotel to run a command on a computer, disable security software, provide a one-time passcode, send card details by email, or sign in through a link in a message when the same task can be done from the platform’s own dashboard. Anything on that list is hotel phishing, without exception.

Hotel Phishing That Never Touches Email: Vishing and QR Codes

Filtering has become good enough that determined attackers increasingly route hotel phishing around it. Verizon’s 2026 report found that 41% of social engineering breaches used a vector other than email, and its simulation data shows the shift is rational: the median click rate for email phishing simulations was 1.4%, while phone-centric simulations ran around 2% — roughly 40% higher.

The call that sounds like your IT provider

Voice phishing works spectacularly well against a front desk. The caller is friendly, technical, in a hurry, and knows the name of your PMS and your general manager. They need the duty manager to approve a sign-in prompt, read out a code, or install a “remote support” tool before the morning rush.

The joint advisory on Scattered Spider — published by the FBI and CISA with the UK’s NCSC and other international partners, and updated in July 2025 — describes the technique precisely. The group posed as employees to convince IT and help-desk staff to reset passwords and transfer multi-factor authentication to a device the attacker controlled, and ran spearphishing and vishing operations that “frequently occur over several calls”, specifically to learn what a help desk requires before attempting the reset.

What hotel phishing looks like when it lands on a hospitality business

Two large US hospitality and casino operators disclosed exactly this shape of incident in September 2023. Caesars Entertainment told the SEC it had identified suspicious activity “resulting from a social engineering attack on an outsourced IT support vendor”, and that the attacker obtained a copy of its loyalty programme database including driving licence and social security numbers for a significant number of members.

MGM Resorts quantified its own disruption in an SEC filing: an estimated negative impact of approximately $100 million to adjusted property EBITDAR for September, plus under $10 million of one-off costs — and, most instructive for a hotelier, occupancy of 88% in September against 93% in the same month a year earlier. A social engineering attack moved the occupancy line by five points. A 60-room independent is not a harder target than these organisations; it is an easier one.

The “guest in room 214” pretext

A different call, aimed at a different weakness. The caller claims to be a guest, gives a room number, and asks the agent to confirm the booking name, the card ending, the arrival date or the company on the reservation. Each disclosure is small. Together they are enough to social-engineer the real guest, or your finance team, later.

The fix is a scripted refusal that protects the agent: no guest details are confirmed by telephone, ever, and the caller is invited to come to the desk with identification. Staff need written permission from the GM to be unhelpful.

Quishing at the desk and in the car park

QR codes are now standard in hospitality — menus, WiFi joins, parking payments, feedback forms — and they are a near-perfect hotel phishing vector because the destination is invisible until after the scan and a sticker costs nothing. Barracuda’s researchers have documented attackers splitting a single malicious code across two images, so scanners see two harmless pictures rather than one code, and nesting malicious codes inside legitimate ones.

Their explanation of why it works applies directly to a hotel lobby: QR codes cannot be read by humans, so they raise no red flags, and they move the target onto a personal phone, away from the company perimeter and its protection. A weekly walk round to confirm every displayed code is the one you printed is a genuinely effective control that costs ten minutes.

Business Email Compromise: When Hotel Phishing Becomes an Invoice

Credential theft is the intrusion. Business email compromise is usually how it gets paid for, and hotels present an unusually rich set of payment flows: laundry, food and beverage suppliers, agency staff, commission, maintenance contractors and refurbishment projects.

The scale of the hotel phishing payout

The FBI’s Internet Crime Complaint Centre recorded 24,768 business email compromise complaints in its 2025 report, with reported losses of $3,046,598,558 — an average of roughly $123,000 per complaint. Phishing and spoofing was the single most reported crime type by volume, at 191,561 complaints. Those are US reporting figures, but the economics are the reason your reservations inbox is worth attacking from anywhere in the world.

The supplier bank-detail change

The classic. From inside a compromised mailbox — yours or your supplier’s — the attacker sends a polite notice that bank details have changed, attaching headed paper. Because the thread is genuine, everything reconciles. Our business email compromise playbook sets out the verification standard: any change to payment details is confirmed by voice on a number you already held, never a number supplied in the email.

Gift cards and payroll diversion

Two smaller but persistent variants of the same fraud family, seen across all sectors rather than hotels specifically. A message from the “GM” asks a duty manager to buy gift cards for a guest gesture. A message from a “staff member” asks payroll to update bank details before month end. Both are low value individually and both work often enough to keep being sent.

Why hotels lose these more often than they should

Three reasons hotel phishing converts to loss here, all fixable. Payment authority frequently sits with one person. Invoices arrive by email as a matter of routine. And the finance function in a single property is often part-time or shared across sites, so whoever approves a payment may not know the supplier well enough to notice that the tone is wrong.

Why MFA Alone No Longer Stops Hotel Phishing

If your security position is “we turned on MFA”, you are protected against the attacks of five years ago. Modern hotel phishing kits are built specifically to defeat app-based and code-based factors.

Adversary-in-the-middle, explained without jargon

Imagine the fake sign-in page is not a copy but a window. When your reservations manager types the password, the attacker’s server passes it straight to the real Microsoft sign-in. Microsoft asks for the second factor, the attacker relays that prompt too, and your manager approves it because it is genuine. The sign-in succeeds, and the attacker keeps the session cookie the real service issued.

That cookie is a valid, already-authenticated session. Changing the password afterwards does not necessarily invalidate it. This is why “we reset her password” is not an incident response.

Device code and consent abuse

A related technique never shows a fake page at all. The attacker starts a legitimate device sign-in, sends the resulting code to the target with a plausible pretext, and asks them to enter it on the real Microsoft page. Everything the user sees is genuine; the token that comes out the other end goes to the attacker. Microsoft’s advice, published alongside its analysis of the actor it tracks as Storm-2372, is to block device code flow wherever possible using conditional access.

MFA fatigue and push bombing

The cruder cousin. An attacker who already has the password triggers approval prompts repeatedly, often at three in the morning, until somebody taps approve to stop the phone buzzing. The Scattered Spider advisory lists exactly this — repeated notifications until an employee presses accept. Number matching makes it much harder and costs nothing.

The help desk reset that undoes everything

The most under-defended path of all, and the one that produced both casino incidents above. A convincing caller persuades whoever holds administrative rights — your IT provider, or a manager with the admin console — to reset a password or enrol a new authenticator. Every technical control you own is bypassed by one helpful human. Your provider needs a documented caller-verification standard, and you should ask them for it in writing today.

Authentication methodStops password theftStops proxy phishingFront desk practicality
Password onlyNoNoSimple, and indefensible
SMS one-time codePartlyNoPoor: personal mobiles on shift
Authenticator code or pushYesNoWorkable, needs number matching
Passkey on the staff deviceYesYesGood on fixed desk machines
Hardware security keyYesYesBest for shared desks and admins
Certificate on a managed deviceYesYesStrong, needs device management

The practical reading for hotel phishing defence: hardware keys on shared front desk machines and every administrative account, passkeys for named managers, and authenticator apps with number matching as the floor for everyone else. The Scattered Spider advisory’s single top-line mitigation is worth quoting to any sceptical owner — “Enable and enforce phishing-resistant multifactor authentication.”

Hotel Phishing and the Guest Data You Are Legally Holding

A compromised reservations mailbox is not only an operational problem. In the UK it is very likely a personal data breach with a statutory clock attached, and good cybersecurity practice here is inseparable from your legal position.

What a reservations mailbox actually exposes

Work through a typical inbox honestly and you will find names, home addresses, phone numbers, email addresses, arrival and departure dates, room numbers, identity document scans, dietary and accessibility requirements that constitute health data, corporate affiliations, and — despite every policy telling guests not to — payment card details sent in plain text.

The Information Commissioner’s Office publishes a retrospective review of phishing cases that makes the consequences concrete. In one penalty case a single phishing email reaching a company’s accounts mailbox was forwarded internally, leading to malware across 283 systems and 16 accounts, twelve of them privileged, and the encryption of personal data belonging to up to 113,000 people, including special category data. Structurally, that is a hotel reservations inbox.

The 72-hour clock

Under UK GDPR, a personal data breach that poses a risk to individuals must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. The clock starts at awareness, not at the conclusion of your investigation, and “we were still checking” is not a defence for missing it.

Two practical consequences. You need a defined moment at which awareness is established, and you need enough logging to answer “what did they access” — because if you cannot show what was reached, you may have to assume the worst.

Card data changes the picture again

If card details are in the mailbox you are also in scope for payment card obligations alongside the ICO’s. PCI DSS v4.0.1 requirement 5.4.1 expects processes and automated mechanisms to detect and protect personnel against phishing attacks, and it stopped being a future-dated recommendation on 31 March 2025. Requirement 4.2.2 prohibits sending unprotected card numbers by end-user messaging technologies such as email, SMS or chat — which is exactly what a guest does when they helpfully email their card details to reservations@.

Note what 5.4.1 does and does not say. Awareness training alone does not satisfy it; the standard’s guidance points to mechanisms such as DMARC, SPF and DKIM alongside anti-malware controls. Our hotel PMS security guide covers the wider data-handling picture.

Where Cyber Essentials fits

If you are certifying, note that the question set changed this year. IASME’s current question set, Danzell, was published in February 2026 and applies to applications registered from 26 April 2026, assessed against the Cyber Essentials Requirements for IT Infrastructure v3.3. Multi-factor authentication is a mandatory requirement for all cloud services where it is available, and failing to implement it is an automatic assessment failure. Our Cyber Essentials for hotels guide maps the rest.

Email Authentication: Stopping Hotel Phishing Sent in Your Name

Everything above is about mail arriving. Email authentication is about mail leaving — specifically, stopping criminals sending mail that claims to be your hotel to your guests, your suppliers and your own staff.

Why hotels break email authentication more than most

A typical property sends legitimate mail from a startling number of places: Microsoft 365, the PMS, the booking engine, the channel manager, a marketing platform, a reputation tool, a spa or restaurant reservation system and the payment provider. Every one needs authorising, and when a marketing agency is added on Friday without telling IT, alignment breaks.

That is why so many hotels sit on a permissive DMARC policy for years. Nobody is confident that tightening it will not silently stop confirmation emails, and confirmation emails are revenue.

Getting to enforcement without dropping bookings

Do it in stages. Start with a monitoring-only policy and collect reports for at least a fortnight, ideally a month covering a full marketing and billing cycle. Inventory every sender the reports reveal — there will be more than your list. Authorise the legitimate ones properly, then move to quarantine for a portion of mail, then to full rejection.

The UK tooling has changed, and older guidance is now wrong

One current point worth flagging: the NCSC retired its free Mail Check and Web Check services on 31 March 2026, pointing organisations towards commercial external attack surface management tooling and its own replacement checks. If your runbook still says “review Mail Check monthly”, it needs rewriting. A hotel with no monitoring at all is simply blind to whether its domain is being abused.

Be honest about what this buys you

Email authentication stops criminals impersonating your domain. It does not stop hotel phishing that arrives from somewhere else, and as the 2026 hospitality campaign showed, an attacker who relays through a legitimate sending platform produces mail that authenticates perfectly. Do it because it protects your guests and your brand, not because it protects your inbox.

Technical Controls That Cut Hotel Phishing Risk in Microsoft 365

Most UK hotels run Microsoft 365, and most are running a fraction of what they already pay for. These are the settings that move the needle.

Preset security policies are the fastest hotel phishing win

Microsoft ships Standard and Strict preset security policies that apply its recommended anti-spam, anti-malware and anti-phishing settings against hotel phishing and keep them updated as guidance changes. For a small property with no security staff this is the highest-value hour of work available: apply Strict to managers, finance and reservations, Standard to everyone else.

Impersonation protection for your brand and your partners

Anti-phishing policies in Defender for Office 365 let you protect named users and specific domains against impersonation, and add mailbox intelligence, which learns normal sender patterns and flags the unusual. Hotels should protect the general manager, the finance contact and the owner, plus the domains of the booking platforms and channel manager you actually use. This is the control most likely to catch a hotel phishing attempt that a busy reservations agent would wave through.

Safe Links, Safe Attachments and the report button

Safe Links checks URLs at click time, which matters because attackers weaponise a link after delivery. Safe Attachments detonates files in a sandbox before release. And the built-in report button turns every member of staff into a sensor, feeding submissions back for analysis instead of leaving suspicious mail sitting in a folder. Zero-hour auto purge, which is included for all cloud mailboxes, then retracts messages later found to be malicious from inboxes they already reached.

The licence reality check

CapabilityBuilt-in (all cloud mailboxes)Defender P1 (Business Premium, E3)Defender P2 (E5)
Anti-spam and anti-malwareIncludedIncludedIncluded
Spoof intelligence and quarantineIncludedIncludedIncluded
Zero-hour auto purge for emailIncludedIncludedIncluded
User and domain impersonation protectionNoIncludedIncluded
Mailbox intelligence impersonationNoIncludedIncluded
Safe Links and Safe AttachmentsNoIncludedIncluded
Investigation toolingMessage trace onlyReal-time detectionsThreat Explorer, Threat Trackers
Attack simulation trainingNoNoIncluded
Automated investigation and responseNoNoIncluded

For most independent hotels, Business Premium is the sensible floor: it carries the impersonation protection and click-time link checking that ordinary spam filtering does not. Groups with a security function get real value from the higher tier’s simulation, hunting and automated investigation features. If you are on the built-in tier only, you have no impersonation protection at all, which is the specific control the lures in this article are designed to evade.

Identity Controls That Survive a Hotel Phishing Click

Email filtering reduces how much reaches your team. Identity controls decide what happens when something gets through anyway, which is the assumption you should plan on — the NCSC is explicit that no training package, phishing simulations included, can teach users to spot every phishing attempt.

Passkeys and keys at the front desk

Phishing-resistant authentication binds the credential to the real website, so a hotel phishing proxy page cannot replay it. In hotel terms that means hardware security keys plugged into fixed front desk and back-office machines, and passkeys for managers on their own devices. Start with the accounts that can move money or change configuration.

Conditional access that fits a rota

Sensible baseline rules for a single property: block sign-in from countries you never operate in, require a compliant or managed device for administrative access, require reauthentication for finance and admin roles, block device code flow, and flag impossible-travel sign-ins for review. None of that interferes with a night auditor doing their job.

Break glass, and the 3 a.m. problem

Every tenant needs at least one emergency access account, excluded from conditional access, with a long stored credential and monitoring on its use. And every hotel needs a documented answer to the 3 a.m. question: who does the night auditor call, on what number, when something looks wrong and the GM is asleep? Write it on a card and tape it to the desk.

Building a Hotel Phishing Training Programme That Sticks

Annual e-learning does not change behaviour at a front desk. What works is short, role-specific and repeated, and it has to acknowledge that your staff will keep opening attachments because that is the job.

Train the role, not the workforce

A reservations coordinator, a night auditor and a finance assistant face different lures and need different rules. Three tailored fifteen-minute sessions beat one generic hour, and they can be delivered at handover rather than pulling people off the floor.

Teach a procedure, not a suspicion

“Be vigilant” is not a control. Give the team three concrete rules instead. Any request for payment details, bank changes or credentials is verified by voice on a number you already had. Any sign-in prompt or code you did not personally trigger is denied and reported. Any instruction to run a command, paste text into a dialog or disable security software is an attack.

Close the hotel phishing onboarding gap

Hospitality turnover means a proportion of your team on any given night joined recently. If hotel phishing training happens once a year, a new starter can work for eleven months without it. Move it into the first week of induction, and cover the report button in the same session as the till and the key cards.

Set the expectation from the top

The NCSC’s guidance on defending organisations against phishing is organised into four layers — making it difficult for attackers to reach your users, helping users identify and report suspected phishing, protecting the organisation from the effects of successful phishing, and responding quickly to incidents. Notice that only one of the four is about spotting emails. A hotel phishing programme that spends all its effort on layer two is three-quarters unbuilt.

Running Hotel Phishing Simulations Without Wrecking Morale

Simulated hotel phishing is useful and easy to get wrong. Done badly it produces resentment, gaming and a management report nobody believes.

Measure reporting, not clicking

Click rate is the number everybody reports and the wrong one to optimise. Verizon’s 2024 analysis of awareness exercise data found that 20% of users reported phishing in simulations, and that 11% of the users who clicked also reported it. That second figure is the valuable one: a person who clicks and then tells you gives your responders a head start, and a person who clicks silently does not.

A team with a 4% click rate and a 55% report rate is far safer than a team with a 2% click rate and a 5% report rate, because the second team is telling you nothing about the real campaign that arrived the same morning.

Why speed beats accuracy

The same report measured how quickly people fall for hotel phishing and every other kind: a median of 21 seconds to click a malicious link after opening the email, and another 28 seconds to enter data — under a minute in total. You are not going to out-deliberate that. What you can change is the gap between the click and the report, which is why the reporting number is the one to publish.

Fair hotel phishing lures and unfair ones

A simulated booking amendment, a fake platform notice or an impersonated supplier invoice are fair: they mirror the genuine threat. Fake bonus announcements, fake redundancy notices and fake disciplinary letters are not. They produce a spike in clicks and a permanent loss of trust, and the trust is worth more.

What to do with a repeat clicker

Not discipline. Ask what they were doing and you usually find a process problem — the accounts inbox receives genuine payment-detail changes weekly, so a person there has no reliable way to distinguish. Fix the process, add a technical control, and give that individual short coaching rather than a warning.

A realistic hotel phishing exposure model

Numbers help managers commit. Take a 180-bedroom UK hotel with four monitored mailboxes and model the volume explicitly. Reservations receives 120 messages a day, the front desk 60, events 25 and accounts 15 — 220 in total. Over a year that is 80,300 messages (220 × 365). If one message in 400 is a hotel phishing attempt, the property faces roughly 200 attempts a year (80,300 ÷ 400 = 200.75), distributed as below.

Modelled annual hotel phishing attempts by inbox — 180 bedrooms, 1 in 400 messages
Reservations, 43,800 messages a year 110 attempts
Front desk, 21,900 messages a year 55 attempts
Events, 9,125 messages a year 23 attempts
Accounts, 5,475 messages a year 14 attempts

At Verizon’s median simulation click rate of 1.4%, that model produces about three clicks a year (200 × 0.014 = 2.8). At a more pessimistic 3%, it produces six (200 × 0.03 = 6). Neither is zero, which is the entire argument for identity controls that survive a click.

Hotel Phishing Reporting Culture: Making It Safe to Say "I Clicked"

Every technical control in this guide buys you time. Reporting is what converts that time into a contained incident rather than a discovered one.

The sixty-second rule

The gap between a click and a report is the whole game. An account reported within a minute is usually a non-event. The same account reported the following Tuesday is a full investigation with a notification decision attached.

Never punish the reporter

The NCSC puts this more directly than most vendors will: training should reassure users that they will not get in trouble if they report phishing incidents, because employees who are afraid for their jobs will not report mistakes. The ICO’s own guidance says the same thing in one line — foster a no-blame culture to encourage reporting.

If an agent who reports a click is disciplined, or even visibly embarrassed, you have bought silence for the price of one conversation. The public position, from the GM, has to be that reporting quickly is correct behaviour, with no penalty attached — including for the person who clicked.

One button, one number, no judgement calls

Do not ask a night auditor at 3 a.m. to assess whether an email is malicious. Ask them to press the report button, and if they interacted with it, ring one number on a card at the desk. That is the entire procedure and it should fit on an index card.

Your Hotel Phishing Incident Response Playbook

When something does get through, the difference between a bad week and a very bad quarter is whether the first hour is scripted. This is the sequence for a suspected account compromise.

The first hour

ScenarioFirst actionSecond actionDo not
Credentials entered on a fake pageRevoke sessions, then reset the passwordAudit MFA methods and inbox rulesAssume the reset alone is enough
Attachment opened, machine behaving oddlyIsolate the device from the networkPreserve it for investigationWipe and reimage immediately
Command pasted after a fake promptIsolate and treat as compromisedReset every credential used on itTrust an antivirus all-clear
A code was read out to a callerRevoke sessions and re-enrol MFACheck for newly registered devicesWait to see if anything happens
Payment made to changed detailsCall the bank to attempt recallReport the fraud, review the threadEmail the supplier from that mailbox
Card details found in a mailboxContain, then notify your acquirerStart the ICO risk assessmentForward the evidence around by email
Extranet account compromisedReset in the platform, revoke sessionsCheck payout details and guest messagesLeave guest messaging unreviewed

The first day

Establish the scope of the hotel phishing incident: which mailboxes, which sign-ins, from where, and what was accessed. Hunt for the things designed to outlive your reset: forwarding rules, inbox rules, delegated permissions, registered authenticators, application consents and OAuth grants, and — where a device was involved — persistence in both the Run and RunOnce registry keys. Then decide, formally and with a timestamp, whether the 72-hour reporting duty is engaged. Our Microsoft 365 business email compromise response plan has the detailed checklist.

The first week

Notify anyone who needs notifying after a hotel phishing breach, including guests where the risk to them is real — and remember the Sekoia research: compromised hotel accounts have been used to defraud guests directly, so your guests may be the ones under attack next. Brief the team honestly about what happened, which is the strongest training you will ever deliver. Then fix the control that failed and rehearse the same scenario as a tabletop exercise a month later. The hotel disaster recovery plan is where this connects to your wider continuity arrangements.

What Hotel Phishing Costs a UK Property

Owners commit budget to numbers, not to threat descriptions, so hotel phishing needs a price tag. Here is a defensible way to size it using published UK trading figures rather than vendor scare statistics.

The revenue model

Knight Frank’s UK Hotel Dashboard for Q3 2025, built on HotStats data, put regional UK year-to-date total revenue per available room at £124.70, gross operating profit per available room at £38.50, average daily rate at £107.50 and occupancy at 75.9%. Apply those to a 175-bedroom regional property.

Total revenue is about £21,823 a day (175 × £124.70) and gross operating profit about £6,738 a day (175 × £38.50). A three-day outage of booking and check-in systems therefore puts roughly £65,468 of revenue and £20,213 of gross operating profit at risk (3 × £21,823 and 3 × £6,738).

The reputational tail

The harder hotel phishing cost is the one that arrives afterwards. MGM’s filing recorded occupancy five percentage points below the prior year in the month of its incident. Apply the same five-point fall to our 175-bedroom hotel for one month at £107.50 average daily rate and the lost room revenue is about £28,219 (175 × 30 × 0.05 × £107.50), before any food, beverage or events knock-on.

Modelled impact on a 175-bedroom regional UK hotel (Knight Frank / HotStats, Q3 2025 year to date)
Revenue at risk, three-day booking and PMS outage £65,468
Room revenue lost, one month five points below occupancy £28,219
One day of total revenue £21,823
Gross operating profit lost, three-day outage £20,213

Setting hotel phishing costs against the cost of prevention

Every control in the ninety-day plan below costs a fraction of one day’s revenue at this property. Hardware security keys for a dozen accounts, a licence uplift and a few days of configuration land comfortably inside £21,823. That is the comparison to put in front of an owner, not a national breach statistic.

A 90-Day Hotel Phishing Hardening Plan

Almost every hotel that reads a guide like this does nothing, because the list is long and the property is busy. Here is the same material as a sequence, weighted so the cheapest high-impact work lands first.

WindowActionOwnerCost
Days 1–30Apply Strict presets to managers and finance, Standard to allIT providerTime only
Days 1–30Enable number matching, block device code flow, deploy the report buttonIT providerTime only
Days 1–30Write the payment verification rule and the 3 a.m. cardGMTime only
Days 1–30Replace shared logins with named accounts and delegated mailboxesIT providerLicences
Days 31–60Hardware keys for admin, finance and front desk machinesIT providerLow capital
Days 31–60Impersonation protection for GM, finance and partner domainsIT providerTime only
Days 31–60Role-based hotel phishing training for reservations, desk and financeGM and providerLow
Days 31–60Start DMARC monitoring and inventory every sending systemIT providerLow
Days 61–90Move DMARC to quarantine, then rejectionIT providerTime only
Days 61–90Run the first simulation and publish the report rate, not the click rateGMLow
Days 61–90Tabletop the compromised reservations mailbox scenarioGM and providerTime only
Days 61–90Get your provider’s caller-verification standard in writingGMFree

If you only do four things

Apply the preset policies, put hardware keys on the accounts that can move money, write down the payment verification rule, and deploy the report button with a stated no-blame position. Those four cost very little and close most of the realistic hotel phishing paths into a single property.

Hotel Phishing FAQ

Is hotel phishing really worse than in other industries?

The volume is comparable; the defence is not. The 2025/2026 Breaches Survey found only 30% of food and hospitality businesses treat cyber security as a high senior-management priority, against 72% of businesses overall. Add published inboxes, high turnover, card data and out-of-hours operation and you have the gap attackers are exploiting.

We are a 40-room independent. Are we too small for hotel phishing?

No, and size is largely irrelevant. The documented hospitality campaigns address the role rather than the person and land in shared inboxes across whole countries at once. Smaller properties are often easier because there is no security team and one person approves payments.

Our staff already did a phishing course. Isn’t that enough?

Not on its own, and no hotel phishing course ever will be — the NCSC says so plainly: no training package, phishing simulations included, can teach users to spot every phishing attempt. Training reduces the rate. Identity controls, filtering and a fast reporting path handle what gets through.

Does multi-factor authentication solve hotel phishing?

It solves password theft; it does not solve proxy phishing, device code abuse or a help desk that resets an account for a convincing caller. Assume a determined attacker can defeat app-based codes and push approvals, and put phishing-resistant methods on the accounts that matter most.

What should a front desk agent do at 3 a.m. if they think they clicked?

Press the report button, then ring the number on the card at the desk. No assessment, no waiting for the morning, no deleting the email. With a median of under a minute between opening a phishing email and handing over data, speed of reporting matters far more than accuracy of diagnosis.

Do we have to tell the ICO every time?

No — only where a personal data breach poses a risk to individuals. But you must assess it promptly and document the decision either way, and where reporting is required the deadline is 72 hours from awareness.

How does this fit with our other hospitality IT work?

Directly. Multi-factor authentication, malware protection and secure configuration all sit inside Cyber Essentials, and hotel phishing defence overlaps heavily with certification work you may already be doing. Our IT support for hotels page explains how we run this as a managed service, and our hotel WiFi security guide covers the network side of the same estate.

References