Row wavy Shape Decorative svg added to bottom

Your Winter Security Checklist: Small Steps That Make a Big Difference

Winter is a good time to take stock. The team gets a breather, and there's finally a moment to look after the things that often get pushed to the back of the queue. Security is usually one of those things.
Seekom Winter Checklist

It doesn't have to be complicated. A few simple habits go a long way towards keeping your property and your guests safe online. So here's a quick checklist. Run through it with your team and you'll be in good shape going into the busy season.

Clean up your user accounts:

This is the one most properties skip, and it's probably the most important. Had a staff member leave in the last six months? A seasonal worker who came and went? Log into your Seekom account and check who still has access. Old accounts that are no longer in use are an open door, and one that's easy to close.

While you're there, make sure every team member has their own individual login. Shared logins might feel convenient, but they make it impossible to know who did what, and they're much harder to secure.

Switch on Two-Factor Authentication:

If you haven't already enabled Two-Factor Authentication (2FA) on your Seekom account, winter is the perfect time to sort it out. 2FA means that even if someone gets hold of a team member's password, they still can't get in without a second verification step. It's one of the simplest and most effective things you can do to protect your account, and it takes about five minutes to set up.

Our support team is happy to walk you through it. Just give us a call or drop us a message during business hours.

Stop sharing passwords:

We know, we know. It's easier to just tell the new person the password. But shared passwords are one of the most common ways accounts get compromised.

The good news is there's no reason to share passwords in Seekom. Every account can have unlimited individual users, so everyone gets their own login with their own access level. Set it up once and you'll never need to share a password again.

Update your passwords, not just your staff list:

Removing old user accounts is step one. But if a former team member knew your passwords, changing the locks matters too. Go through your key systems - your PMS, email accounts, OTA extranets, social media, and update any passwords that might have been shared with someone who’s no longer with you.

While you're at it, make sure passwords aren't being reused across different platforms. If one account gets compromised and the password is the same everywhere, the damage spreads fast. A password manager can take the headache out of keeping track of them all.

Tighten up your email security:

Your email account is the key to the kingdom. If someone gets into it, they can reset passwords for pretty much everything else. Yet email is often the last thing people think to protect.

A few quick wins:

  • Enable two-factor authentication on your business email account, not just your PMS
  • Check who has access to shared inboxes like info@ or reservations@ and remove anyone who no longer needs it
  • Be careful about what you include in automated guest emails. Avoid putting full booking reference numbers or personal details in subject lines where they can be easily read
  • If you get an email that looks like it's from a supplier or OTA asking you to update payment details or click a link, call them directly to verify before doing anything

Watch out for phishing emails:

Phishing is when someone sends you an email pretending to be a trusted source, trying to get you to hand over your login details or click a dodgy link. It happens more than you'd think in the accommodation industry.

The recent Booking.com breach is a good example of how this plays out. Once scammers had real guest data, including booking details and contact information, they used it to send convincing messages that looked like they came from a legitimate source. Guests were contacted via WhatsApp and email and asked to verify their payment details.

A few things to remind your team:

  • Seekom will never ask for your password by email or phone
  • If an email asks you to click a link and log in, go directly to the website instead of clicking
  • When in doubt, call the company directly using a number you already know
  • If something feels off, it probably is. Trust your gut and check with us

Review what data you're collecting from guests:

Take a look at your booking form and ask yourself: do we actually need all of this? A lot of properties collect more than they need. Dates of birth, passport numbers, dietary requirements for a property that doesn't serve meals. The less guest data you hold, the less there is to lose if something goes wrong.

Strip your forms back to what you genuinely use. It's better for your guests, better for your liability, and it makes your life simpler too.

Make sure your payment setup is secure:

If you're taking online payments, it's worth checking that 3D Secure (3DS) authentication is active on your SeekomPay setup. It adds a bank-level verification step for cardholders, which reduces fraud and protects your revenue from chargebacks.

Not sure if you have it switched on? Drop our support team a message and they'll check for you.

Start with whatever feels most overdue for your property. Even ticking off one or two things from this list will put you in a stronger position than you were yesterday. And if you need a hand with any of it, our support team is here. Give us a call or flick us a message and we’ll help you get sorted.

undraw_wireframing_nxyi (2) (1)

Note: Something you may not know is that we also build websites. Many of our customers have Seekom-built, self managed websites with full control, backed by our expert setup and support. If you’re interested in finding out more, please get in touch.

Contact Us

4/234 Wakefield Street, Te Aro, Wellington 6011
Phone (NZ) : +64 4 974 9588
Phone (UK) : +44 20 3835 5939
Support: support@seekom.com
Websites: webhelp@seekom.com

Connect With Us

 Copyright 2025 © Seekom Limited (NZ owned)

Third-Party Impersonation Scam: What Every Property Needs to Know

Third-Party Impersonation Scam: What Every Property Needs to Know

As we continue to improve security awareness and resilience across our platform, we’d like to highlight another critical threat targeting the hospitality sector. Earlier last year, a campaign was impersonating Booking.com and delivering credential-stealing malware. This article explains what is happening, why it matters to you, and what you can do to protect your business.

What’s happening

A new phishing scam is targeting accommodation providers by pretending to be Booking.com. The emails look convincing and often claim there is an urgent issue with a guest review or your property listing.

If someone clicks the link, they are taken to a fake Booking.com page that asks them to run a command on their computer. If they do, malware is installed, giving attackers access to passwords, payment information, and other sensitive data.

This campaign is active across multiple regions, including Oceania, and specifically targets hospitality businesses such as hotels, motels, and holiday parks.

Why this is relevant for your property

If your property uses a PMS like ours and connects to online booking channels, you are part of the hospitality ecosystem that this campaign is targeting. Here’s why it matters:

  • Malware could steal passwords, payment information, or guest data, affecting your PMS, booking channels, and property operations.
  • Staff members may receive a legitimate-looking email, click a link, and accidentally trigger the malware.
  • Once inside, attackers may use stolen credentials to commit fraud, misdirect payments, or access sensitive guest or property data.
  • This scam tricks people into copying and running a command, so it can bypass normal security protections that usually stop standard phishing links.

In short: your property’s risk exposure can increase not just through your own systems, but via any third-party booking channel, partner, or staff email.

How the attack works

1. A staff member receives an email that appears to come from Booking.com. Examples: a guest review request, a complaint about a review, an account-verification alert.

Figure 1. Sample phishing email, purportedly requiring the recipient to address negative feedback about a hotel.
Figure 1. Sample phishing email, purportedly requiring the recipient to address negative feedback about a hotel.
Third-Party Impersonation Scam: What Every Property Needs to Know - How the attack works figure 2
Figure 2. Sample phishing email, purportedly requiring the recipient to verify their Booking.com account.

2. The email links to a webpage that looks like a Booking.com account verification page. The page shows a fake CAPTCHA prompt.

3. The user is instructed to press a keyboard shortcut, then paste and run a command (which the malicious webpage has placed into their clipboard). This command launches the malware.

4. Once installed, the malware can steal passwords, payment information, or give attackers remote access.

5. Attackers then use that access to commit fraud or further compromise your systems.

What you can do

Here are practical steps your property and staff should follow to reduce risk.

Enable MFA on all critical systems and email accounts.
Train staff to recognise phishing red flags:
  • Be cautious of urgent messages like “Your account will be suspended” or “Respond now.”
  • Watch for typos or misspelled domains (e.g., “seecom.com” or “micros0ft.com”)
  • Be wary of emails containing unexpected attachments.
Use email filtering and anti-phishing tools (e.g. Microsoft Defender).
Verify URLs before clicking – hover over links to check authenticity.
Run regular malware scans on all devices.
Monitor sign-in logs for unusual activity.

Why this matters for us at Seekom

At Seekom, we are committed not just to delivering great PMS software, but also to helping our partner properties protect their business and reputation. Phishing campaigns like this one (impersonating Booking.com) show that cybersecurity isn’t just an IT issue - it is a business and people issue.

A compromised staff account can affect property operations, revenue, guest experience, and even how you use our system or third-party channels. By educating staff, implementing strong controls, and staying vigilant, you can significantly reduce your risk.

Related case: business email compromise

For those of you who receive the HAPNZ monthly newsletter, you may have seen an article from AON Insurance about a professional services firm in New Zealand that suddenly faced a business email compromise targeting their administration/accounts manager. The threat actor gained unauthorised access to the business’s mailbox, resulting in a significant breach.

The breach was discovered when approximately 400 clients of the firm received emails with “overdue statements” containing altered bank information.

For those who haven’t seen it, you can read the full article here: How Cyber Insurance Saved This Small Business

undraw_wireframing_nxyi (2) (1)

Note: Something you may not know is that we also build websites. Many of our customers have Seekom-built, self managed websites with full control, backed by our expert setup and support. If you’re interested in finding out more, please get in touch.

Contact Us

4/234 Wakefield Street, Te Aro, Wellington 6011
Phone (NZ) : +64 4 974 9588
Phone (UK) : +44 20 3835 5939
Support: support@seekom.com
Websites: webhelp@seekom.com

Connect With Us

 Copyright 2025 © Seekom Limited (NZ owned)