Copy article

Have you or your business been hacked?

ended 28. March 2025

A Newspage friendly on a national newspaper is looking for businesses or people who have been hacked to feature as case studies — along with tips from experts in this field. If that's you, tell us a bit about it: were you yourself targeted directly or were you a victim of a wider hack? How did it feel like psychologically to know you had been hacked and was sensitive information stolen? How was it resolved? Also, if you're a cyber security expert, what basic (or advanced) steps can people take to protect their devices against being hacked? And do enough people take the threat of hacking seriously enough in this day and age? 

3 responses from the Newspage community

Copy all

Copy

I’m embarrassed to admit we were hit with a two-pronged attack — though thankfully, over 80% of our bookings come directly through our own website, with only around 20% via booking channels like Airbnb.

The breach started with a change in our email filtering, which allowed some (but not all) Airbnb messages through. At the same time, hackers accessed our Airbnb account, added multiple mobile numbers for two-factor authentication, and quietly changed the payment details — with all alerts filtered so we never saw a thing.

Over a few months, they let some payouts through to avoid suspicion, but we still lost over £50,000. After many sleepless nights, suspecting even Airbnb’s help centre had been compromised and being told there was nothing that could be done, Airbnb eventually reimbursed us in full.

It feels shameful for savvy tech users like us to have been caught out. But it’s been a sharp lesson, and one that’s led to much tighter processes and a whole new level of vigilance.
Copy

We've never been hacked or lost sensitive info, but we have been cloned. There are many ways to secure your website, and the service providers are getting better at stopping hacks from happening. But one increasingly common form of fraud is to set up a new website, copying the images and content from a legitimate website, and use the reputation of that brand trick customers who think they are buying from a real brand into handing over their card details through a fake checkout. It's happened to us a couple of times as we're an established brand in our industry, and we've had the fraudsters' sites taken down before any damage happened. But it's a surprisingly difficult process, as the domain registrars and web hosting companies don't seem to want to get involved. For consumers, if you're unsure, check the reviews, make sure the domain names match up, and look out for the absurdly high discounts these fraudsters use to lure you in. If the offer seems too good to be true, it probably is.
Copy

While my business hasn't been hacked, a number of my clients have (which is what typically drives them to come to me!). Realistically the biggest risk factor in being hacked are the people within your organisation. It is really important that people follow sensible rules with passwords - password123 is easy to crack, toasthummingbirdbanana not so easy. It is also important that your team know not to click on, reply to and especially open any attachment on an email if they have any suspicions about the email at all - if in doubt delete it, if it was genuine they will send it again (and remember if it's an email from your bank, it really isn't going to come from a gmail address!). As I advise all of my clients though, you cannot make your business 100% hackproof, but rather like your car in a public car park, you can't make it impossible to steal, you can make it much harder to steal than the cars either side.