Kaspersky’s Global Research and Analysis Team (GReAT) has identified a new wave of cyberattacks by the long-active threat group RevengeHotels, which is now using Artificial Intelligence (AI) to steal hotel guests’ payment data.
Active since 2015, the group has evolved its techniques, with many of its latest malicious programs containing AI-generated code, making them more sophisticated and difficult to detect.
Global Reach of Attacks
While hotels in Brazil have been the primary victims, Kaspersky has observed similar attacks worldwide. With South Africa and Kenya among Africa’s top tourist destinations and Nigeria a hub for business travel, analysts warn that no hotel—regardless of size or location—is immune.
How the Attacks Happen
The group relies on phishing emails disguised as reservation requests or job applications. Once an unsuspecting staff member clicks on these, malware known as VenomRAT is installed, granting attackers access to payment information and other sensitive guest data. The emails are often highly convincing, using domains that appear legitimate.
“Cybercriminals are increasingly applying AI to make familiar schemes like phishing far more deceptive,” said Lisandro Ubiedo, GReAT expert at Kaspersky. “For hotel guests, this significantly raises the risk of card and personal data theft, even at trusted, well-known establishments.”
Kaspersky’s Recommendations
To reduce risks, Kaspersky advises hotels and businesses to:
-
Be cautious with emails – Don’t open links or attachments from unknown senders, even if messages appear genuine.
-
Strengthen security tools – Use advanced solutions such as Kaspersky Next, which deliver real-time protection, threat visibility, and investigation/response capabilities (EDR and XDR).
-
Refine antispam filters – Customise filters to block phishing attempts that mimic trusted services.
-
Avoid unexpected attachments – Even files from official-looking sources may contain ransomware or spyware.
As the hospitality industry continues to digitise, experts stress that cyber resilience must be prioritised alongside guest experience to protect both operations and customer trust.


