Scammers Target Indian Hotels & Homestays Via Fake Contact Numbers

CloudSEK’s researchers found several google accounts posting similar-looking photos on hotel listings.
Updated on
April 19, 2023
Published on
March 24, 2023
Read MINUTES
7
Subscribe to the latest industry news, threats and resources.
  • Category: Adversary Intelligence
  • Industry: Hospitality
  • Motivation: Financial
  • Region: India
  • Source*A - Reliable; 1 - Confirmed by independent Sources

Executive Summary

THREAT

  • Threat actors are uploading images showcasing their phone numbers on google listings of hotels.
  • When an unsuspecting user contacts these phone numbers they are asked to make an advance payment for reservation confirmation.
  • ~71% of the targeted audience fell prey to these scams.

IMPACT

  • The fake custom care numbers are being misused by scammers to lure customers of hotels which is resulting in a monetary loss for the victim. 
  • Brand image loss to the hotel.

MITIGATION

  • Run aggressive awareness campaigns to educate users about the ongoing scams.
  • It is recommended to identify and immediately suspend or takedown such google accounts spreading Fake Customer Care Numbers.
  • Book only via trusted channels and avoid putting upfront deposits.

Analysis and Attribution

Information from the Post

  • CloudSEK’s researchers found several google accounts posting similar-looking photos on hotel listings.
  • Multiple sets of these images had the same background but different phone numbers were written on them.
  • These phone numbers are written in such a way that OCR could not read them but are readable by humans.

Images used by the threat actors
Images used by the threat actors


Analysis of the Numbers

An in-depth analysis of the numbers suggested the following points were observed in this campaign:

  • Threat actors are not limited to any geographical area and have posts across various states in India. A major concentration of this campaign was observed in the pilgrimage cities (Jagannath Puri, Ujjain, Varanasi).
  • Hotels and homestays from all price categories are being targeted in this campaign.
  • Threat actors are regularly creating new google accounts and using new phone numbers to keep the scam running. 
  • It remains unknown whether this campaign is operated by a single actor or a group of people, however, our research was able to uncover multiple google accounts advertising different numbers. 
Breakdown of spam calls made by 19 mobile numbers

  • Truecaller records indicate that around 71% of the calls from the 19 fake numbers discovered during our research were answered by individuals who could become victims. On average, 126 calls were made from each number.
  • Notably, the names associated with the scanned numbers on Truecaller profiles did not match the names linked to their Google accounts.
  • Multiple google accounts were observed advertising different phone numbers in a single hotel listing. (For more information please refer to the Appendix section)
  • As observed in previous instances of fraudulent customer care schemes, the perpetrators, in this case, employed a combination of the three primary telecommunications providers, with the majority of the registered numbers originating from the eastern and northeastern regions of India.

List of Google Accounts & Phone Numbers Used by Scammers

Account Link

Phone number

Registration Location

https://www.google.com/maps/contrib/100655498214153111375

8617443086

8144321738

Odisha

https://www.google.com/maps/contrib/112826966846275215419

9692182843

Odisha

https://www.google.com/maps/contrib/107950071569607620602

8837005580

North East

https://www.google.com/maps/contrib/117663204237854812749

7866082095

West Bengal

https://maps.google.com/maps/contrib/101022430140869405389

9356028167

Maharashtra

https://maps.google.com/maps/contrib/116594188144988868782

7060038324

UP West

https://www.google.com/maps/contrib/103243183673942049603

8486332291

Assam

https://www.google.com/maps/contrib/114115566872117343026

7847860829

Orissa

https://maps.google.com/maps/contrib/101884051664544899304

9641421769

West Bengal

https://maps.google.com/maps/contrib/103567652347825257792

9395722631

Assam

https://maps.google.com/maps/contrib/103361386941780052565

9395722631

Assam

https://maps.google.com/maps/contrib/102617568761677590022

8822966642

Assam

https://maps.google.com/maps/contrib/107559494506389582120

9893976133

Madhya Pradesh

https://maps.google.com/maps/contrib/110934943370971605745

7001747344

West Bengal

https://maps.google.com/maps/contrib/116525534014228069194

7853960279

Odisha

https://maps.google.com/maps/contrib/116731513050316651823

9339417294

West Bengal

https://www.google.com/maps/contrib/104840289281495527709

6002590983

Assam

https://maps.google.com/maps/contrib/111434268937751769108

7890287325

Kolkata

References

Appendix

Image added by an account named “Mahaveer Gujar” on Goroomgo Tapati Villa hotel

Image added by an account named “Amit Kumar” on the same hotel Goroomgo Tapati Villa

Contribution page of the google account revealing all photos uploaded through the account


Get Global Threat Intelligence on Real Time

Protect your business from cyber threats with real-time global threat intelligence data.. 30-day free and No Commitment Trial.
Schedule a Demo
Real time Threat Intelligence Data
More information and context about Underground Chatter
On-Demand Research Services
Dashboard mockup
Global Threat Intelligence Feed

Protect and proceed with Actionable Intelligence

The Global Cyber Threat Intelligence Feed is an innovative platform that gathers information from various sources to help businesses and organizations stay ahead of potential cyber-attacks. This feed provides real-time updates on cyber threats, including malware, phishing scams, and other forms of cybercrime.
Trusted by 400+ Top organisations