{"id":49459,"date":"2025-02-22T11:29:44","date_gmt":"2025-02-22T11:29:44","guid":{"rendered":"https:\/\/kede.com.br\/news\/family-says-security-loophole-has-been-exposed-in-holiday-site\/"},"modified":"2025-02-22T11:29:45","modified_gmt":"2025-02-22T11:29:45","slug":"family-says-security-loophole-has-been-exposed-in-holiday-site","status":"publish","type":"post","link":"https:\/\/kede.com.br\/news\/family-says-security-loophole-has-been-exposed-in-holiday-site\/","title":{"rendered":"Family says security loophole has been exposed in holiday site"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"\">\n<div data-component=\"byline-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<div data-testid=\"byline-new\" class=\"sc-b42e7a8f-0 haItSe\">\n<div data-testid=\"byline-new-contributors\" class=\"sc-b42e7a8f-12 fcCDwR\">\n<div class=\"sc-b42e7a8f-5 evAEAB\">\n<div><span class=\"sc-b42e7a8f-7 khDNZq\">Holly Hamilton and Daniel Lynch<\/span><\/p>\n<p><span>Consumer Fight Back<!-- --><\/span><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-18fde0d6-0 ejjhCR\">\n<div data-testid=\"hero-image\" class=\"sc-a34861b-1 jxzoZC\"><img sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/2bd3\/live\/4e95a600-f043-11ef-afe3-3909ee34e697.jpg.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/2bd3\/live\/4e95a600-f043-11ef-afe3-3909ee34e697.jpg.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/2bd3\/live\/4e95a600-f043-11ef-afe3-3909ee34e697.jpg.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/2bd3\/live\/4e95a600-f043-11ef-afe3-3909ee34e697.jpg.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/2bd3\/live\/4e95a600-f043-11ef-afe3-3909ee34e697.jpg.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/2bd3\/live\/4e95a600-f043-11ef-afe3-3909ee34e697.jpg.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/2bd3\/live\/4e95a600-f043-11ef-afe3-3909ee34e697.jpg.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/2bd3\/live\/4e95a600-f043-11ef-afe3-3909ee34e697.jpg.webp\" alt=\"BBC Marion Tyler is sitting on a grey armchair. She is looking directly at the camera with a sombre expression. She has brown shoulder length hair and red lipstick on. She is wearing a silver necklace. \" class=\"sc-a34861b-0 efFcac\"\/><span class=\"sc-a34861b-2 fxQYxK\">BBC<\/span><\/div>\n<\/div>\n<p><figcaption class=\"sc-8353772e-0 cvNhQw\">Marion Tyler &#8220;felt sick&#8221; when she realised she had been targeted by scammers<!-- --><\/figcaption><\/p>\n<\/figure>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">A family that was targeted by scammers fear their experience has exposed a security loophole in an online travel agent&#8217;s booking platform.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">Marion Tyler, from County Antrim, unwittingly called a scam number when attempting to phone loveholidays about a booking and then shared details that allowed fraudsters to access her account.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">Later, when trying to resolve the issue, Ms Tyler&#8217;s daughter-in-law found she could access her mother&#8217;s account even after log in details had been changed.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">She said she believed scammers &#8220;must be getting in again and again&#8221; because of an issue with the firm&#8217;s authentication process, but loveholidays has backed its system.<!-- --><\/p>\n<\/div>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">It told <!-- --><a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/sounds\/play\/p0ksrh3q\" class=\"sc-c9299ecf-0 bZUiKB\" rel=\"noopener\">BBC Radio Ulster&#8217;s Consumer Fight Back<!-- --><\/a> programme it was sorry to hear about Ms Tyler&#8217;s experience but it was &#8220;confident that the industry standard two-factor authentication process ensures our platform and our customers&#8217; data is secure&#8221;.<!-- --><\/p>\n<\/div>\n<p><h2 class=\"sc-518485e5-0 kRvAla\">How did the holiday scam work?<!-- --><\/h2>\n<\/p>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">Marion Tyler had booked a holiday through loveholidays.com for herself, her daughter and two grandchildren to Lanzarote in August. <!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">When she wanted to pay off some of her balance, she phoned a number, from an online search, that she believed to be the firm but was actually a scam company. <!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">The scammers tricked Ms Tyler into thinking she was speaking to loveholidays and she shared some details about her booking.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">It is unclear how the scammers accessed a one-time passcode link that was sent to Marion&#8217;s email. This allowed them full access to her loveholidays reservation.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;I genuinely believed it was loveholidays, because she knew all the details of our holiday,&#8221; said Ms Tyler.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;She knew right down to the flight times, she knew everything.&#8221;<!-- --><\/p>\n<\/div>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">After moving Ms Tyler to a WhatsApp conversation, scammers tricked her into transferring \u00a32,000, saying it would save her money on her holiday.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">But when Ms Tyler rang the real loveholidays the next day to confirm her remaining balance, she was told the firm had not received any payment from her.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;I actually felt sick. I was in a state of panic,&#8221; she said.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;I was absolutely gutted and devastated. It really did affect me and I didn&#8217;t sleep. I was annoyed at myself for being stupid enough to do it and for falling for it.<!-- --><\/p>\n<\/div>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;It&#8217;s soul destroying, how easily they were able to access it and get that very definite information about the holiday.&#8221;<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">Ms Tyler alerted loveholidays to the scam and was advised to change the email address on her booking and add a password.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">But, while she was on the call with loveholidays, changes were made to her booking &#8211; scammers were changing the destination of her holiday and the passenger times.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">Ms Tyler&#8217;s family feared even after updating their security details, scammers could still access her booking.<!-- --><\/p>\n<\/div>\n<p><h2 class=\"sc-518485e5-0 kRvAla\">&#8216;I was in shock&#8217;<!-- --><\/h2>\n<\/p>\n<figure>\n<div data-component=\"image-block\" class=\"sc-18fde0d6-0 jFCfG\">\n<div data-testid=\"image\" class=\"sc-a34861b-1 jxzoZC\"><img src=\"https:\/\/www.bbc.com\/bbcx\/grey-placeholder.png\" class=\"sc-a34861b-0 cOpVbP hide-when-no-script\"\/><img sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/6425\/live\/acb85630-f04b-11ef-9d67-696683900f64.jpg.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/6425\/live\/acb85630-f04b-11ef-9d67-696683900f64.jpg.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/6425\/live\/acb85630-f04b-11ef-9d67-696683900f64.jpg.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/6425\/live\/acb85630-f04b-11ef-9d67-696683900f64.jpg.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/6425\/live\/acb85630-f04b-11ef-9d67-696683900f64.jpg.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/6425\/live\/acb85630-f04b-11ef-9d67-696683900f64.jpg.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/6425\/live\/acb85630-f04b-11ef-9d67-696683900f64.jpg.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/6425\/live\/acb85630-f04b-11ef-9d67-696683900f64.jpg.webp\" alt=\"Marie is sitting in a grey armchair, looking directly at the camera with a slight smile. She is wearing a black long sleeved top and has long blonde hair with a fringe. \" class=\"sc-a34861b-0 efFcac\"\/><\/div>\n<\/div>\n<p><figcaption class=\"sc-8353772e-0 cvNhQw\">Marie Tyler says she did not have to log-in again after details were changed<!-- --><\/figcaption><\/p>\n<\/figure>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">Her daughter-in-law, Marie Tyler, took over and contacted loveholidays.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">During that call, she opened her internet browser and logged on to the firm&#8217;s website &#8211; having previously used the computer to access her mother-in-law&#8217;s account, she expected to have to log-in again as the account details had been changed.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">To her surprise, however, the site brought her straight into Ms Tyler&#8217;s booking. <!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;I was in shock,&#8221; Marie Tyler said.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;I was getting ready to get the verification link sent over to me. I thought: &#8216;I&#8217;m in!'&#8221;<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">She said she told loveholidays&#8217; customers service team that the scammers &#8220;must be getting in again and again because you&#8217;re not reauthenticating people&#8221;.<!-- --><\/p>\n<\/div>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">The family has reported the scam to Action Fraud and contacted the Information Commissioner&#8217;s Officer over their data protection concerns. <!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">They are also working with their bank to recover the money.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">Loveholidays told Consumer Fight Back they were &#8220;sorry to hear about Marion&#8217;s experience after calling a number that was not associated with loveholidays and, unfortunately, falling victim to a scam&#8221;.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;The fraudster managed to maintain access to her booking through their cache. We have been in touch with the family and have secured the booking by transferring it to a new account with a new reference number,&#8221; the company said.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;We are confident that the industry standard two-factor authentication process ensures our platform and our customers&#8217; data is secure, with the issue, in this case, stemming from the customer handing this access over to the scammer.&#8221;<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">The firm said it had &#8220;initiated further steps&#8221; should future customers find themselves in a similar position, including improving internal processes &#8220;to ensure access to the account is immediately revoked when we are alerted that a customer&#8217;s account is compromised&#8221;.<!-- --><\/p>\n<\/div>\n<p><h2 class=\"sc-518485e5-0 kRvAla\">&#8216;We have to put it in perspective&#8217;<!-- --><\/h2>\n<\/p>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">Ms Tyler still hopes to go on the holiday later this year with her daughter and grandchildren.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;I&#8217;m actually really still annoyed about it.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;It&#8217;s not pleasant, it&#8217;s not nice and it&#8217;s a lot of money, but it&#8217;s not the worst thing that can happen in your life.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">&#8220;We have to put it in perspective. What else can you do?&#8221;<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fYAfXe\">You can listen to the full story on <!-- --><a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/sounds\/play\/p0ksrh3q\" class=\"sc-c9299ecf-0 bZUiKB\" rel=\"noopener\">Consumer Fight Back with Holly Hamilton on BBC Sounds.<!-- --><\/a><\/p>\n<\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.bbc.com\/news\/articles\/c778xg2zgrvo\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Holly Hamilton and Daniel Lynch Consumer Fight Back BBC Marion Tyler &#8220;felt sick&#8221; when she realised she had been targeted by scammers A family that was targeted by scammers fear their experience has exposed a security loophole in an online travel agent&#8217;s booking platform. Marion Tyler, from County Antrim, unwittingly called a scam number when [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":49460,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[48],"tags":[6712,968,2996,1121,1771,4014],"_links":{"self":[{"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/posts\/49459"}],"collection":[{"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/comments?post=49459"}],"version-history":[{"count":1,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/posts\/49459\/revisions"}],"predecessor-version":[{"id":49461,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/posts\/49459\/revisions\/49461"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/media\/49460"}],"wp:attachment":[{"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/media?parent=49459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/categories?post=49459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kede.com.br\/news\/wp-json\/wp\/v2\/tags?post=49459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}