Suspected Phishing or Compromised Account: Emergency Plan

If you believe a staff member accidentally entered their Cloudbeds credentials on a fake login page, or if you suspect your account has been accessed without your permission, act immediately. Speed matters.

How this usually happens

The most common attack targeting Cloudbeds users looks like this:

  1. A staff member searches "Cloudbeds login" in Google.
  2. A malicious sponsored ad appears at the top of the results. It looks identical to the real Cloudbeds login page.
  3. The staff member enters their username, password, and even their active MFA code.
  4. The attacker captures these credentials in real time and logs into the real Cloudbeds platform within seconds before the MFA code expires.

This last point is important to understand. Standard MFA codes, including authenticator app codes and SMS codes, do not protect against this type of attack. The attacker is not breaking your security, they are using your real credentials, live, the moment you hand them over. This is called a real-time phishing attack or session hijacking.

This is why Passkeys and Hardware Security Keys are the only login methods fully immune to this attack — see the prevention section below.

Suspicious Emails Claiming to Be From Cloudbeds:

If you receive an email that looks like it is from Cloudbeds but seems suspicious, do not click any links or download any attachments.

If you have already clicked a link or entered your Cloudbeds login details on a suspicious page, change your Cloudbeds password right away and check your account for any unfamiliar activity.

Step 1: Change the password and contact support immediately

Log in to Cloudbeds using the official link (https://hotels.cloudbeds.com/auth) and go to AccountAccount menu icon.png-> My ProfileProfiles.png-> Change Password. This prevents the attacker from using the stolen credentials to open any new sessions.

Then contact Cloudbeds Support right away. Our team can terminate all active sessions on your account immediately — this is the fastest way to remove anyone currently logged in under your credentials. Changing your password alone does not end sessions that are already open.

When contacting support, provide:

  • Your property ID
  • The email address of the compromised account
  • The approximate date and time the incident occurred
  • Whether you suspect credentials were entered on a fake page, or whether you noticed suspicious activity in your account directly

If you cannot log in because the attacker has already changed your password, go to the login page and click "Forgot password?" to trigger a reset via your registered email, then contact support immediately.

Step 2: Check your Activity Logs thoroughly

Go to AccountAccount menu icon.png-> SettingsSettings icon.png->Activity Log and review everything that occurred during the window you believe the account was compromised.

What to look for:

  • Guest data exports — Any reservation list or guest data export is the highest-priority item to identify. If an export ran during the compromise window, assume that guest contact data was collected.
  • New user accounts created — Attackers sometimes create a backdoor account to maintain access after you change your password.
  • Permission changes — Look for any role upgrades or permission expansions applied to existing users.
  • Property profile or settings modifications — Payment details, notification emails, or channel manager settings may have been changed.
  • Guest messages sent via GX (Whistle) — Fraudulent messages may have been sent to guests impersonating your property.
  • New API keys created — A new API key gives an attacker continued programmatic access even after you change your password. Revoke any keys you do not recognize immediately.
  • Booking or reservation modifications — Check for any reservations that were created, cancelled, or modified unexpectedly.

Document everything you find in the Activity Log and include it when you contact support. This information helps our Security team assess the full scope of the compromise.

Step 3: Audit your user list and disable unauthorized access

Go to AccountAccount menu icon.png-> SettingsSettings icon.png-> UsersUsers.png and look for anything unexpected.

What to check:

  • Any accounts added recently that you do not recognize
  • Any users with elevated permissions (Owner or Manager roles) that should not have them
  • Any users with access to data exports (Reservation List, Guest Data)

If you find an unauthorized user: use the three-dot menu next to their name and select Disable User immediately.

As a precaution, temporarily remove data export permissions from any unverified staff accounts while you investigate.

  A note on payment data: Full credit card numbers and CVV codes are never visible through standard Cloudbeds account views. Cloudbeds uses tokenization, which means card data is stored by our payment processor and is not accessible to anyone browsing your account — including an attacker who gains access. Your guests' payment details are not at risk from this type of compromise.

  Guest data in list views is now partially masked. Email, phone, home address, ID document number, and date of birth are automatically hidden in reservation and guest list views, making bulk data harvesting from a stolen login significantly harder. See: Protecting Your Account With Hidden Guest Details

Step 4: Force MFA re-enrollment for all staff

Once you have secured the account and audited the activity, require all staff to reset their MFA. Even if only one account was directly compromised, it is good practice to treat a phishing incident as a property-wide security event.

To reset MFA for a staff member:

  1. Go to AccountAccount menu icon.png-> SettingsSettings icon.png-> UsersUsers.png
  2. Click the three-dot menu next to the user's name
  3. Select Reset MFA Status

Repeat this for every staff account. Each user will be prompted to set up a new MFA method on their next login.

This is also the right moment to migrate any remaining staff from SMS or authenticator app codes to Passkeys or Hardware Security Keys — the only methods that cannot be replayed by an attacker in real time. See: 
Setting Up Passkeys and Set up Alternative MFA Methods

Step 5: Notify guests who may have been contacted during the compromise

If your Activity Logs show that guest messages were sent via GX (Whistle) during the period you believe the account was compromised, those guests should be notified promptly.

What to do:

  1. Identify the guests who received messages during the compromise window by reviewing your GX message history.
  2. Contact those guests directly using your official property email or phone — not through GX until you are certain the account is fully secured.
  3. Let them know that your property's account was briefly accessed without authorization, that no payment data was exposed, and that any messages they received during that window did not come from your team.
  4. If any guests were asked to click a link or provide personal information via those messages, advise them not to act on those requests and to contact your property directly.

Being proactive with guests reduces the risk of further fraud and protects your property's reputation. If you are unsure which guests to contact, our support team can help you identify the affected window from the Activity Logs.

Step 6: Report the suspicious link to Cloudbeds

Forward the suspicious URL or phishing email to support@cloudbeds.com with the subject line: Phishing

Include:

  • The URL of the fake page (copy from your browser's address bar — do not click it again)
  • The date and approximate time the incident occurred
  • The email address of the affected staff member

Our security team can initiate domain takedown procedures against fake sites, protecting other Cloudbeds customers who might encounter the same link.

Preventing this in the future

Switch to Passkeys or Hardware Security Keys — the only truly phishing-proof login methods.

Standard MFA codes — including authenticator app codes and SMS — can be captured and replayed by an attacker in real time. Passkeys and Hardware Security Keys are cryptographically bound to the official Cloudbeds domain and will not work on a fake login page. Even if a staff member enters their email on a fraudulent site, there is nothing for the attacker to capture or replay.

  • Passkeys use your device's built-in biometrics (fingerprint or face scan) and require no additional hardware. How to set up a Passkey How to set up a Passkey 
  • Hardware Security Keys (YubiKeys) are small USB devices that plug into any computer. Ideal for shared front desk terminals where a personal phone is not practical. 

Bookmarking the official login page is also strongly recommended as a second layer of protection for all staff.

  🔖 Official login: https://hotels.cloudbeds.com/auth Print this and tape it next to every front desk terminal. Never search "Cloudbeds" in Google to find the login page.

For more on securing your property's login setup, see: Admin Guide - SMS & Email MFA and Choose the Best Login & MFA Method for You.

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.