When the Wolf Is Already Inside the House

by Marco Soares

10 min read

How Easily Summer Vacations Can Get Ruined

Every summer, hundreds of millions of people book accommodation through the world's major travel platforms. They trust the interface they land on. They trust the property listed on it. They enter their card details and they go on holiday.

That chain of trust — platform, then property, then payment — is what the online travel industry is built on. It has taken decades and enormous investment to establish. It generates hundreds of billions in annual transactions. And the platforms at its centre have poured significant resources into protecting it: fraud detection systems, two-factor authentication, security teams, customer protection programmes.

None of that investment is wasted. But it also cannot fully address a problem that doesn't originate inside the platforms themselves. Because the most damaging attacks on online travel don't breach platform security. They bypass it entirely. One fake login page at a time.

When We Only See the Tip of the Iceberg

The scale of fraud in online travel is genuinely difficult to pin down — not because the data doesn't exist, but because not all of it is published, and not all that is published reflects what is actually happening.

Juniper Research estimated travel fraud losses at over $21 billion globally in 2023. Ravelin's Global Fraud Trends 2025 report, based on a survey of merchants across ten countries, found that the average travel, ticketing or hospitality company loses $11 million to fraud per year — and noted that the most damaging consequence is not the direct financial loss, but the erosion of customer trust.

Then there is the number that reframes everything else. In March 2026, the FTC's associate director testified before a US Congressional committee that reported consumer fraud losses reached $15.9 billion in 2025 — up 430% since 2020. She was equally clear that those figures represent a fraction of actual losses — because only 2% to 6.7% of fraud victims ever file a report. The numbers the industry sees are not the problem. They are the visible tip of it.

The iceberg is not a metaphor. It is the operating reality of this industry.

Crime-as-a-Service Is a Highly Scalable Business Model

To understand why this fraud is so persistent — and why no amount of platform-side investment has yet been able to stop it — you need to understand where the attack actually begins.

The web is, by design, neutral. It was built for openness, not authentication. Anyone can register a domain that closely resembles a travel platform. Anyone can obtain a valid TLS certificate — the padlock in the address bar that was once treated as a mark of legitimacy. Anyone can build a pixel-perfect replica of a booking platform's login page. This is not a failure of any platform's security architecture. It is a structural characteristic of the web itself — one that no organisation, however well-resourced, can resolve from within its own perimeter.

The barriers to impersonation have effectively collapsed at the infrastructure level. A single sustained campaign, documented by Netcraft in November 2025, traced a threat actor who had registered over 4,300 domains impersonating major travel brands — purpose-built to steal payment data from travellers who believed they had landed on a platform they knew. These are not isolated registrations. They are industrialised operations, timed to peak seasons, running at machine speed, on infrastructure entirely outside any platform's control.

Two Victims. One Stolen Key.

Here is where the mechanics matter — because they reveal something that receives far too little attention.

The fraud does not begin with the traveller. It begins upstream, with the accommodation unit.

Hotels, guesthouses, and short-term rental hosts manage their listings and reservations through the travel platforms they partner with. They log in regularly. They respond to booking requests, manage pricing, update availability. Their access to those platforms is how they run their business.

That access is what criminals target first.

A property manager receives what appears to be an official communication from their booking platform — a login prompt, an account verification, a policy update requiring immediate attention. The page they land on looks exactly right. Same logo, same layout, same familiar interface. It is not the real platform. It is a clone, built to capture their credentials silently and invisibly.

Microsoft Threat Intelligence documented exactly this pattern in a sustained campaign running from December 2024, targeting hospitality organisations across North America, Europe, Asia and Oceania — fake platform pages designed to harvest the login credentials of accommodation partners.

The property manager logs in. Their credentials are captured. And then the criminal does something that makes this attack particularly devastating: they go quiet.

They wait. Because now they have access to the property's real account — its genuine reservation history, its upcoming guests, their contact details, their booking references, their check-in dates. Everything needed to approach those guests convincingly, from inside a platform both parties trust.

The guest receives a message. It arrives through the platform they booked on. It references their real reservation. It comes from the property they chose. It asks them to re-confirm payment details ahead of arrival, or to use a link for express check-in, or to verify their card to secure the booking. The message is entirely plausible — because it originates from a legitimate account, on a legitimate platform, about a legitimate stay. And because the vast majority of messages guests receive through these channels are entirely genuine, there is no trained instinct to doubt this one. That is not a flaw in the guest. It is the design of the attack.

The Guardian documented exactly this experience in June 2025 — 'Your reservation is at risk': beware the booking scam — reporting how guests receive messages through legitimate platform channels, from genuine hotel accounts, asking for card details to secure a stay they have already booked. The message arrives with urgency. It references the real reservation. It gives a deadline. It includes a link. And because it arrives through the platform the guest already trusts, the usual instincts — check the sender, look for odd email addresses — simply do not apply. Action Fraud recorded 532 reports of this exact pattern in the UK between June 2023 and September 2024, with victims losing a total of £370,000. Given what the FTC's own underreporting data tells us about how rarely fraud victims come forward, that figure almost certainly represents a fraction of what actually occurred.

The traveller has done nothing wrong. The hotel has done nothing wrong. They are both victims of the same crime — one that began on a fake login page the property manager had no reliable way to identify as such.

This is not a user education problem. It is a structural one.

The advice to "check the URL carefully" or "call the property to verify" does not survive contact with this attack. The URL closely mirrors the real platform. And by the time the guest is being approached, the criminal is already operating from inside the property's own account — with access to the same communications channel the guest would use to verify.

cover

On the internet, nobody knows you're a dog - We used AI to make this "Wolf Is Already Inside the House". Cybercriminals use AI to send hyper-personalized messages to every accommodation unit and every guest on your booking platform. Effortlessly and relentlessly.

The Web Was Not Built to Answer This Question

Both sides of this attack share a single root cause: the web provides no native mechanism for either the accommodation unit or the traveller to verify they are on the genuine platform before they act.

This is not a criticism of how platforms are built. It is a description of how the web is built. A travel platform can invest in every layer of internal security and still be unable to answer the one question that matters most at the moment a property manager opens a login page or a traveller clicks a booking link: is this actually us?

That question has no answer on the open web — unless someone builds one. Not from inside the platform, but at the level of identity itself. The answer has to be anchored in something the web's neutral infrastructure cannot replicate: the organisation's own registered trademark, used by the brand itself to sign and claim its digital properties. Not assessed. Not scored. Claimed — by the organisation, as an expression of the legal right they already hold.

Think of it as the next evolution of the padlock. Where a TLS certificate tells you a connection is encrypted, a trademark-anchored identity tells you something far more specific: this website was signed by the organisation that legally owns this brand. A hyper-personalised mark — unique to each organisation, federated across every digital property they choose to claim — that exists inside a closed ecosystem of verified trademark holders. Criminals cannot buy their way in. They cannot obtain a registered trademark under false pretences the way they obtain a TLS certificate or register a lookalike domain. Before any brand is onboarded onto Proofmarked, the Trademark Clearinghouse confirms that the organisation is the rightful, registered holder of the mark they intend to use as their digital identity. No verified ownership, no entry. The web's neutral tools are available to anyone. This one is not.

That is the missing piece. And it is one the travel industry's most trusted platforms are uniquely positioned to deploy — not as a security patch, but as a layer of first-party trust that benefits every participant in their ecosystem.

What First-Party Proof Actually Looks Like

This is the model Proofmarked was built to deliver. And in the context of online travel, the chain it serves maps precisely onto the problem.

The travel platform integrates Proofmarked, anchoring its verified brand identity to its registered trademark — confirmed through Proofmarked's collaboration with the Trademark Clearinghouse. The platform then distributes the Proofmarked browser extension to their accommodation partners — free of charge, as a natural extension of the trusted ecosystem they have already built.

The accommodation unit now has something the web has never offered them before: a clear, first-party signal at the moment of login. Not a probabilistic assessment of whether a site looks legitimate — but a direct answer to a binary question: has the platform itself signed and claimed this page as theirs? The travel platform has marked their digital properties with their trademarked identity. The extension reads that mark. Either it is present, or it is not. A clone cannot produce it. It does not hold the trademark. The property manager never surrenders their login. The criminal never gains access to the reservation data. The downstream attack on the guest never begins.

The traveller is protected by the same mechanism. When they visit what appears to be the platform to confirm a booking or respond to a message, the extension reads the platform's own signature — or finds its absence. The fake page, however convincing, cannot carry a mark it was never given the right to hold. Adyen's 2024 Hospitality Report found that one in ten hotel guests have already experienced payment fraud — and that 71% of travellers worry about it. That concern is not irrational. But it is currently unaddressed at the point where it would actually make a difference: the moment before the interaction begins.

And when either party encounters a site claiming to be the platform but carrying no trademark signature, reporting it is effortless. That report feeds directly back into Proofmarked's threat intelligence network — not as a suspicion to be weighed, but as a verified signal: this URL was presented as the platform, and the platform has not signed it. The absence of the mark is the signal. Proofmarked is the engine that circulates it — cascading protection across every accommodation unit and traveller in the network, in near real time, without requiring any manual review or confidence threshold.

The property manager who fell for a convincing fake login page is not negligent — they are a victim of an attack specifically engineered to be indistinguishable from the real thing. Under the Proofmarked model, that changes. Their verified logins protect their own accounts. Their reports of fake platform sites protect their peers. Every property that joins the network makes the ecosystem harder to exploit — for every other property, and for every traveller those properties serve. The entry point becomes the early warning system. The victim becomes the defender. This is the inversion at the heart of what Proofmarked is built for: turning the organisations that fraud targets into the mechanism by which fraud is defeated.

The deeper cost of the current paradigm lands on the platform both parties trusted. The guest defrauded inside what they believed was a secure, familiar environment loses confidence in that environment — quietly, without filing a complaint, often without fully understanding what happened. That erosion is cumulative. The platform's hard-won trust becomes the collateral damage of a crime that began entirely outside its walls. Proofmarked closes the gap before that cost accrues.

The Infrastructure Is Already Running

The fraud infrastructure targeting online travel is not hypothetical. It is live, scaled, and timed for peak season. Microsoft's threat researchers documented a sustained credential-harvesting operation running continuously from December 2024 into 2025, specifically targeting accommodation partners across four continents. The platforms that power this industry have invested heavily in protecting what they can control. What they cannot control is the web itself — and the ease with which it allows their identity to be borrowed by those with no right to it.

That is not a gap that will close on its own. It requires a new layer of trust infrastructure — one that lets platforms answer the question "is this really us?" before the interaction begins, gives accommodation partners a first-party signal at the moment of login, and gives travellers what they have always deserved but the web has never provided: the certainty that the platform they are booking through is genuinely the one they trust. Not through warnings. Not through vigilance training. Through proof — signed by the brand, verified at the source, surfaced at the moment it matters.

Trust, once it is this systematically exploited, does not recover through awareness campaigns. It recovers through proof.


Interested in how Proofmarked's verified trust model works for travel platforms and their accommodation partners? Get in touch or install the free browser extension to see the positive signal of trust in action.