Introduction

The tourism industry is crawling back to pre-pandemic numbers thanks to travel and lockdown restrictions being lifted globally. Unfortunately, cybercriminals have also come up with a new and sophisticated campaign to breach the systems of booking sites, hotels, and travel agencies. Subsequently, the cybercriminals use the systems of the compromised hotel or travel agency to send phishing emails to existing customers.  

Summary of hotel and travel agency phishing scam

  1. The Entry Point – The campaign starts with the threat actor inquiring about a reservation with the hotel or travel agency. Upon booking the stay, the threat actor uses ‘advanced social-engineering techniques’ to inquire about specific or special accommodations.  
  2. Tricking Employees – After establishing a sense of urgency with the hotel employee, the threat actor sends over a URL via email, which supposedly contains crucial documents relevant to their accommodations. The URL provided directs the hotel employee to a genuine hosting site (Google Drive, Dropbox, etc.) and the hotel employee downloads an archive file thinking that it contains important documents.
  3. Malicious Executables – The archive file that was downloaded by the hotel employee contained malicious executables (malware) that would infiltrate the hotel employee’s computer. From there, the malware operates stealthily to capture login credentials, financial information, and other sensitive data without the hotel employees being aware.  
  4. New Target – Once threat actors have successfully compromised the hotel’s system, the threat actors can move onto using the hotel’s communication channel to target legitimate customers.  
  5. Phishing – The threat actors can now send phishing messages disguised as legitimate requests from the compromised hotel or travel agency. The phishing messages will ask for additional credit card verification from the customer. Since the message comes directly from the booking site through a legitimate communication channel, the customer has no reason to doubt the legitimacy of the email.  

How to stay safe

  1. Avoid Clicking on Unsolicited Links – Always be skeptical of unsolicited links, even when they originate from a trusted source. Check URLs for any indicators of deception.  
  2. Take Your Time – Threat actors, phishing emails, and sketchy requests for payments will typically call for immediate action. Take your time to discern any emails that require you to transfer sensitive information.  
  3. Trust Your Instincts – If you are suspicious about a suspicious email, call the hotel or travel agency directly to confirm that the communication is indeed legitimate.  

Richter Guardian can help you navigate complex phishing scams. Your onboarded mobile and endpoint devices are protected; the protection service can detect suspicious links and will work to block insecure websites.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Security advisories
Subscribe to newsletter

Subscribe to receive our latest news and insights in your inbox each week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Protect your digital life by detecting risks before they escalate

Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

24/7 monitoring & threat intelligence
Identity theft & impersonation detection
Fast incident recovery & expert guidance
Have questions after reading?
Blog

Related posts

Older man holding eyeglasses while looking at a tablet

Why Richter Guardian's Digital Executive Protection Works Like a Home Security System

A monitored home security system watches the doors, the windows, and the driveway, and it alerts a real person the moment something looks wrong. Richter Guardian is built around the same underlying idea as a home security system, just applied to a high-net-worth family's digital footprint.

Most high-net-worth families already understand physical home security. A monitored home security system watches the doors, the windows, and the driveway, and it alerts a real person the moment something looks wrong.

Few families would consider their primary residence unprotected in this way.

Yet the equivalent protection is often missing for the digital side of an executive's family life, where far more of their exposure now lives: within personal email accounts, mobile phones, computers, social media profiles, and financial credentials.

Richter Guardian is built around the same underlying idea as a home security system, just applied to a family's digital footprint.

It is worth walking through the comparison directly, because it makes clear what "protection" should include.

Sensors on every door and window, not just the front entrance

A home security system is only as strong as the size of its coverage. A system that only watches the front door leaves every other entry point open. This is why home security systems place sensors on every window, every door, and often the garage too.

Richter Guardian applies this same principle to an executive's digital life on the home and family front. Personal digital protection means every meaningful entry point is covered, not just the obvious one. This includes:

- Personal laptops, tablets and phones, which are frequently the least protected devices in a household.
- Personal and family email accounts, often the single most valuable target since they often double as the recovery method for banking and investment accounts.
- Social media accounts, which can be cloned or impersonated to reach family members, friends, or staff.

Just as an unmonitored side window undermines a home security system's front-door sensor, one unprotected personal device or account can undermine protection everywhere else.

24/7 monitoring, not a sign in the yard

A home security sign discourages some opportunistic activity, but it does not stop a determined intruder, and it certainly does not respond to one.

The value of a real home security system comes from continuous monitoring: sensors that are always active and a monitoring center that is always watching.

The digital equivalent is continuous monitoring for leaked credentials, impersonation, and malware:

- A stolen password sitting on the dark web is like a duplicated house key sitting in a stranger's pocket. It does nothing on its own, but it becomes dangerous the moment someone decides to use it.
- Ongoing dark web and credential monitoring means that exposure is caught before it turns into a break-in, rather than being discovered only after money or data is already gone.

Monitoring that connects you with a real person, not just an app that pings you

When a home alarm is triggered, the value isn't only the alert. It's what happens next.

A monitoring centre verifies the situation and, if needed, contacts emergency services on the homeowner's behalf. Compare that to a security system that simply sends a phone notification and leaves the resident to figure out what to do.

If an issue arises or clarification is required, our concierge support team contacts you in secure, private and discreet manner. Communication may take place through the Guardian mobile app, a phone call, or another agreed-upon channel.

Our Guardian professionals, also known as the Cyber Defence Desk, explain what’s happening in clear language and guide next steps in a way that fits into your broader wealth and risk strategies.

This matters most in the moment it's needed: when there's a convincing call, a strange pop-up, or an unexpected wire request.

When you know exactly who to speak with, and have those questions be answered by a real person, is the difference between a contained incident and a costly one.

Motion sensors around the perimeter, not just the locks

Good home security doesn't rely on locks alone. It adds motion sensors, cameras, and perimeter alerts, so that suspicious activity is noticed even if no door has actually been breached yet.

The digital version of this is reputation and identity protection. A cloned social media profile or an impersonation attempt is a form of activity around the perimeter of a family's digital life, well before any account can be compromised.

Monitoring for that activity, and acting on it early, is what keeps a small warning sign from becoming a full-blown incident involving fraud or reputational harm.

Covering every household under one family's roof, not just one address

Here is where the comparison becomes especially important for high-net-worth families with more than one residence, or with members living in different homes altogether.

A homeowner with a vacation property, or an adult child in a separate residence, would not consider that second home "covered" by the security system installed at the primary address. Each home needs its own protection.

The same is true digitally, and it is often overlooked.

A family's digital exposure does not stop at one address. It follows every family member:

- the adult child at university;
- the parent living independently; and
- the staff working across more than one property.

Each of these people and their accounts and devices represents a separate point of exposure, and each needs to be covered on its own, not assumed to be safe because "the family" has security somewhere.

This is why Richter Guardian's approach extends coverage across the full footprint of a family, not just one principal or one property.

Extended visibility across multiple households means that a family member living somewhere else entirely is not left outside the perimeter simply because they aren't under the same roof.

The value of thinking about digital executive protection this way

None of this is meant to suggest that digital executive protection and home security are the same thing, because they aren't.

The underlying logic that makes a home security system worth having is exactly the logic that should apply to a family's digital exposure: full coverage, continuous monitoring, a real response when something goes wrong, and protection that follows every member of the family, not just one address.

Families who wouldn't leave a single window unmonitored at home are, in many cases, leaving several digital windows wide open without realizing it.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Cityscape towers

Protecting Against Real Estate Wire Fraud

Real estate wire fraud is a scam where criminals impersonate trusted parties to redirect money during a property transaction. For high-net-worth individuals, and executives, the risks can be especially significant.

Introduction

Real estate wire fraud is a scam where criminals impersonate trusted parties to redirect money during a property transaction.

These transactions often involve large wire transfers, and time-sensitive communication between buyers, sellers, lawyers, real estate agents, title companies, notaries, and financial institutions.

Together, these factors make real estate transactions a prime target for fraud.

For high-net-worth individuals, and executives, the risks can be especially significant.

Property purchases and sales may involve large sums of money, multiple advisors, and sensitive personal or financial information. A single fraudulent email or payment can lead to substantial financial loss.

The most important rule is simple: before sending money, always verify wire instructions by phone using a trusted number you already have, not one provided in an email.

Why it matters

Real estate transactions remain a major target for fraud. In 2025, the FBI’s Internet Crime Complaint Center reported more than 12,000 real estate fraud complaints and over $275 million in reported losses. This was higher than 2024, when losses were about $173 million.

These losses show how common and damaging real estate fraud can be. In many cases, the victim believes they are sending funds to a legitimate party, only to discover that the money was redirected to a fraudulent account.

How the attack works

Attackers often begin by gaining access to an email account involved in the transaction or by impersonating one of the parties. They may silently monitor the conversation and wait for the right moment to intervene.

Once attackers understand the details of the deal, they send a convincing email with fraudulent bank details that redirect the money to the attacker. Attackers may impersonate any party involved in the transaction, such as a real estate agent, lawyer, title company representative, or even the buyer or seller themselves.

Because the attacker may know specifics like dollar amounts, property addresses, and names of people involved, the message can look legitimate, making the email extremely convincing.

How to protect yourself

The most effective protection is independent verification. Before sending any wire transfer, call the intended recipient using a trusted phone number that was provided in person, saved previously, or found through an independently verified source.

Do not rely on contact information included in an email containing wire instructions. If an attacker controls the email conversation, they may also provide a fake phone number to “confirm” the fraudulent details.

This is especially important as AI voice cloning becomes more convincing. A phone call is only useful if the number is trusted. When in doubt, use a number you already know or independently verify the number through an official website or previously established contact.

The same approach should be used for any high-value payment, account change, or request involving sensitive financial information.

Red flags to watch for

Be cautious of:

- Last-minute changes to wire instructions

- Pressure to wire immediately

- Email addresses that look slightly off, such as ‘titlecompany.co’ instead of ‘titlecompany.com’

- Request to confirm payment details only via email

- Unusual urgency, secrecy, or changes in communication style

- New bank account details that were not previously discussed

However, a well-crafted attack may not include any obvious warning signs. Rather than trying to decide whether an email “looks suspicious”, treat all wire instructions as unverified until they are confirmed by phone using a trusted number.

Before sending a wire transfer

Before sending funds, take these steps:

1. Confirm the wire instructions by phone using a known, trusted number.

2. Verify the recipient's name, bank name, account number, routing number, and payment amount.

3. Do not use phone numbers or links provided in the same email as the wire instructions.

4. Be especially cautious about last-minute changes.

5. If anything feels unusual, pause the transaction and contact your advisor, bank, or security team.

How Richter Guardian can help you

Richter Guardian can help reduce the risk of wire fraud through proactive monitoring, personal cybersecurity guidance, and expert support to secure accounts, devices, credentials, and identity-related information.

If you are unsure about a transaction, receive suspicious payment instructions, or want added protection before a high-value transfer, contact us.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: Protecting Against Technical Support Fraud

Protecting Against Technical Support Fraud

Tech support fraud remains widespread, with over 30,000 FBI-reported victims in 2022. Learn common tactics—fake calls, pop-ups, remote access—and how to avoid them with Richter Guardian’s help.

Introduction

Cyber criminals have been carrying out technical support scams for over a decade. As technology evolves, so do the techniques of fraudulent tech support scammers, making it difficult for people to discern whether the technical support team they’re speaking to is legitimate. Technical support scams are so common that the FBI’s Internet Crime Report of 2022 reported that ‘Tech Support Crime’ had over 30,000 recorded victims in 2022.  

Summary of a technical support fraud

Technical support scammers use many different techniques to trap people and gain access to their computers and other devices. After they convince you that there is a problem, they request an exorbitant fee in return for their help. Here are two of the most common methods technical support scammers use to trick their victims:

  1. Phone calls, emails and text messages – Technical support scammers may call, email or send a text message and pretend to be a computer technician from Apple, Microsoft, or any well-known technology company. They will assure you that there is a problem with your computer, and request that you give them remote access to your computer to help remediate the issue.
  2. Pop-up warnings – Technical support scammers may trick you with pop-up windows; it may look like an error or warning message from your device, and it may use similar graphics from trusted websites. The pop-up will often provide a phone number that you can call to get help. The phone number will lead to a fraudulent tech support worker.

Recommendations

  1. Stay Informed – Always be skeptical of unsolicited calls, emails or text messages that report a problem with your device.  
  2. Prevent Remote Access – When a technical support scammer has you on the line, they will convince you to provide them remote access to your device in order to run diagnostic tests. Do not provide remote access to your device.  
  3. Trust Your Instincts – If you are suspicious about an unexpected message, call, or request for personal information or money, it is safe to assume it may be a scam.  
  4. Stay Educated – Participate in security awareness sessions provided by your Richter Guardian team, your bank or other trusted organizations.  

We understand that misleading pop-ups or warnings about your device through a call can cause uncertainty. Richter Guardian’s monitoring system and concierge service can give you peace of mind.

Your onboarded mobile and endpoint devices can be monitored by us. If there is a problem with your device, we will contact you to provide specific details about any potential alerts. Our experts can help you remediate the issue.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.