Agent Hooked by Phishing Scam Shares Lessons Learned
by Maria LenhartHere’s a scenario you want to avoid at all costs. Someone hacks into your email database, steals your address book and sends everyone a message – from your very own email address – that you are stranded overseas and need money urgently.
This all-too familiar phishing scam recently befell Linda Koch, CTC, owner of Travel Office, a TRAVELSAVERS agency in Canterbury, N.H. The experience gave Koch both aggravation and a valuable lesson in making passwords secure.
“It could probably have been prevented,” Koch told Travel Market Report. “I have learned a lot about how to prevent this from happening again.”
Tale of a phishing scam
Koch’s trials began when everyone on her Yahoo database received a phony email message, purportedly from Koch, saying she was stranded in Wales and needed money immediately.
Koch was more fortunate than others have been in similar situations.
First, she was notified within a few hours of the scam by a friend in Europe who discovered the message shortly after it was sent out at 4:00 a.m., EST.
“My friend called me at 7:30 in the morning to warn me about the message. I immediately got in and changed my password and then reported it to Yahoo security,” Koch said.
Quick action is critical
Koch’s quick action to contact a security expert via Yahoo’s live chat service meant she was able to retrieve her address book. Had she waited much longer, her database would have been permanently lost, she was told.
“Since it was reported within an eight-hour timeframe, security was able to retrieve the software and reinstall it in my computer,” she said.
Changing her password immediately was also critical, as it prevented the hackers from logging back on and doing more harm.
(A similar phishing scam this month hit another agent with a Yahoo account, Cheryl Clear, CTA, owner of Battlefield Travel in Culpepper. Va. Unlike Koch, Clear was unable to contact Yahoo within the eight-hour timeframe and so lost her entire address book.)
After retrieving her address book, Koch quickly sent an email blast advising everyone in her database that the message about being stranded was a scam. “I also told them that this was not a virus, but strictly a scam to get money,” she said.
Safeguards curb damage
As serious as the situation was, it could have been much worse.
For instance, Koch keeps paper files on each client, including their email addresses, so she would not have lost all their contact information even if her address book had been irretrievable.
Also, the thieves were unable to retrieve any credit card information or other personal data from Koch’s hacked database.
That’s because Koch makes it a practice to never put any credit card numbers from clients – or even home addresses – in any type of email communication.
Restricts info
“In fact, I don’t even input the credit card number when making a booking. I will call a cruise line with the credit card information, even though I know their systems are secure,” she said.
“I was getting calls all day from worried clients, but I was able to reassure them that none of their information had been compromised.”
Password wasn’t hacker-proof
Why were the hackers able to get as far as they did with the phishing scam?
The fault lay with a password that was not nearly secure enough to foil the increasingly sophisticated technology that hackers use to decipher passwords. That’s what Koch learned from both Yahoo support and her nephew, an online security expert for the federal government.
“I thought I already had a tricky password, but my nephew just laughed at me when I told him what it was,” she said. “He told me that if you are using any word that’s in the dictionary, hackers can easily get it.”
Create a secure password
Koch learned that it is essential to create a password that is a combination of letters, both upper and lower case, plus a number and a symbol found at the top of the keyboard, such as an exclamation point or dollar sign.
“If you have a bad password, it doesn’t matter how good the other security is for your computer,” she said.
Change it frequently
“I also learned that I should change my password at least every 90 days – in fact, some large companies have their employees change their passwords every 30 days,” she said.
Koch set up an alert system on her Yahoo account to remind her when it was time to change the password.
More easy precautions
Another safeguard is to avoid passwords that reflect personal information that can be found easily on a Facebook page, Koch advised. The same guidelines apply to security questions used to gain access to online accounts.
“People post the names of their grandchildren, their dogs, where they went to high school on Facebook. All of that information provides clues for hackers.”
Passwords on supplier sites
Not using the same password to access websites and online accounts is another precautionary tip that Koch learned from the security experts.
“I’ve gone to all of the various tour operator and cruise line websites and changed my password for each one,” she said. “Each password should be unique to each site.”
Are agents more vulnerable?
While Koch is not certain that travel agents are more vulnerable than anyone else to phishing scams, she does believe the hackers knew she was a travel agent.
“The word ‘travel office’ is part of my email address, so it’s pretty obvious that I’m a travel agent. It’s possible that I was targeted as someone likely to be traveling.”





