Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

As More People Return to Travel Sites, So Do Malicious Bots

Attacks against travel-related websites are on the rise as the industry begins to slowly recover from COVID-19, new data shows.

With summer holidays, long weekends, and relaxed restrictions on staying at home, the suffering travel industry is seeing some reemerging signs of life: organic visits to car rental websites have grown by 285% since April 1 after a significant drop in traffic during the COVID-19 shutdown.

But as organic growth returns, so have bots carrying out a variety of attacks, including content and price-scraping, hoarding, and malicious attempts to take over user accounts, aka account takeover (ATO), according to a new report from PerimeterX.

"This increase in users is accompanied by an increase in competitive scraping bot requests," PerimeterX Founder and CTO Ido Safruti said in a blog post, referring to the practice where competitors use bots to grab inventory and pricing information from an ecommerce website.

The data shows that competitive scraping-bot requests almost doubled the week of April 20, spiking the last week of April by 544% — and remaining at that level ever since — with a "dramatic increase" in malicious requests from Asia and Europe.

Car rental sites aren't alone, according to PerimeterX. While lodging websites are only seeing 60% of the organic traffic they saw in early March, malicious activity has remained consistent on those sites throughout the pandemic.

"Malicious traffic on this industry did not slow down during this entire period, and we've seen a steady level of scrapers and account takeover (ATO) attacks hitting these sites," writes Safruti.

And while the airline industry is witnessing only a small recovery compared to rental cars, malicious attacks increased 151% by May, and those sites have remained at that level. The malicious bot attacks on airline websites are still not as high as they were before the pandemic, however.

PerimeterX's Safruti says there's reason to believe some of this activity is driven by a coordinated effort. "Large advanced ATO campaigns are in many cases coordinated among crime organizations/actors, and we see large campaigns operating across multiple sites," he said in an email interview. 

Plus, some of the activity isn't criminal, but is likely "competitive warfare."

"Scraping a site's content or pricing is legal (though may break the terms of use of the site). That means there is a market for scrapers, and companies providing data-scraping services and tools for that, and they are selling it out there," he said.

For site operators looking to get a handle on the issue, Safruti recommends checking their logs for anomalies and increased login/failed login attempts, particularly those that don't result in a completed booking.

"Most site operators are aware of the general issue of bots, but not necessarily to the extent that they're impacting their site," he said.

Related Content

Nicole Ferraro is a freelance writer, editor and storyteller based in New York City. She has worked across b2b and consumer tech media for over a decade, formerly as editor-in-chief of Internet Evolution and UBM's Future Cities; and as editorial director at The Webby Awards. ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Overcoming the Challenge of Shorter Certificate Lifespans
Mike Cooper, Founder & CEO of Revocent,  10/15/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-10-22
The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inab...
PUBLISHED: 2020-10-22
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.
PUBLISHED: 2020-10-22
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
PUBLISHED: 2020-10-21
WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it is possible to inject an XSS payload into the owner POST parameter, which does not filter user inputs. By putting an XSS payload in place of a valid Owner Name, a modal b...
PUBLISHED: 2020-10-21
Adobe InDesign version 15.1.2 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .indd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.