What is a Phishing Scam?
Phishing is the fraudulent practice of sending emails purporting to be from reputable companies in order to induce individuals to reveal personal information, such as passwords and credit card numbers.
Are You Really At Risk?
Yes! Your travel partner (supplier) and GDS (for those of you using a GDS) login credentials are extremely valuable and should be kept secure. If your account is compromised, scammers can book fraudulent transactions and you could be liable for significant losses.
How Does Phishing Work?
Typically, a phishing scam will send you an email that appears legitimate. It will typically ask you to log in to approve a change, update some information, or another legitimate sounding purpose. Once you click on the link or button in the email, you are taken to a website that appears legitimate. It may have the company's logo that you would expect. The domain you see in the URL bar of your browser may even be the real domain, however, you are on the scammer's site. They're waiting for you to enter your log in credentials. Once you do, they log them and can log into your real account, change the password to lock you out, and make fraudulent reservations using your account. This is extremely dangerous, especially in a GDS system, where reservations can be ticketed immediately.
How To Spot A Phishing Scam
Take these steps before clicking on emails asking you to log in to a system or providing credit card information:
- Examine the email sender's domain. Often scammers will change the name of the email sender to match the legitimate company, but the domain will not be the company's real domain.
- Urgent deadlines. Scammers will try to create urgency by communicating a short time frame that you MUST take action to avoid some terrible outcome. If an email is asking for urgency, just pause to review the email closely for signs of a scam. If there is some major update occurring with a GDS or one of our travel partners, check with Agency Services before proceeding. Anything major and legitimate, you'll probably hear from us before receiving any kind of email with an urgent request.
- Poor grammar and spelling errors. We all make a typo now and again, but if the email looks like it was written by someone in elementary school, it is probably a scam.
- Emails beginning with unfamiliar greetings. Be suspicious of emails that begin with things like 'Dear user' or that are extremely formal (or informal).
- Link Destination. Where does the link from the email go? Do not click the link, but you can usually hover over a link in most email programs to see where the link goes. Does the link go to some random domain that isn't related to the supposed sender? If so, it's probably a scam.
- Look for the company's logo. Scammers often include the logo of the company, but if there isn't a logo, it should raise your suspicions.
- Too good to be true emails. If the email promises some great reward, it almost certainly is a phishing scam.