Have you been hacked? This is what I found

Ann72
Level 10
New York, NY

Have you been hacked? This is what I found

Several hosts have posted recently about being hacked, and I've been getting more emails than usual from friends reporting hacked Instagram and Facebook accounts.  Nerve-wracking!

 

It seemed a good time to look into things, so I went to Account -> Login & Security, and checked out my device history.  All looked good.  (You can also click this link:  https://www.airbnb.com/review_your_account.)

 

To the right of Login & Security, there's a box that says "Your account security: Medium," so I clicked through to see what could be improved.  It asks to verify your phone number by sending a code.  But I kept getting a message from @Airbnb saying "We can't send a code to this phone number. Try using a different one."  It's a US cell phone number.  I get codes sent to it all the time.  How can I improve my account security if Airbnb can't do its part?

 

Though it's a small thing, it really makes me wonder how secure our accounts really are.

 

29 Replies 29

@Emilia42  That's good!  I don't know why the page says "we verify your phone number every year," but I don't think I've had any interaction like that with @Airbnb.  

 

I removed my payment card, too, and assume I'll just be able to put it in next time I travel.  

 

The important thing is that whatever they post should work.

Ann72
Level 10
New York, NY

Hi @John5097 on your advice I checked with @Stephanie and here's what she said, "The links works for me - perhaps John is not logged into his airbnb host account for the link?"

@Ann72 Ok thanks. I looked at it again. They are two different things, hence the confusion. 

1) Host can simply go to their Account then Log in and Security to see their security level, as you mentioned in your fist post.

Or 

2) The link you posted is for a different security assessment that requires host to create a new password in order to investigate their own account for anything that seems amiss. 

It just wasn't clear to me, as I mentioned it ask for a new password, and wasn't the first process you described. 

I simply went into my hosting account to access my account history and settings. 

The link you posted could also be helpful if an account is already compromised, I would imagine? It just wasn't clear to me at least. This is the first page, and not a link to a host Settings page as first described. 🙂 

PS.. I usually don't click on any link then enter my password or create new password. I can't think of any time I would trust that its from a legitimate source except now that both you and Stephanie say so. But if that's just some email I got claiming to be ABB I wouldn't enter my password, I'd go to my hosting page and sign in. No way I'd just click on some random link and start entering passcodes.. Even though I'm now sure it was well intended. 🙂 

Screen Shot 2022-04-18 at 1.19.41 PM.png

 


@John5097   Yes, I offered two ways of checking and securing your account.

 

My experience with account review was that they ask if you want to change your password, but there is a button marked "Skip" at the bottom, so you can continue without changing your password.

Emilia42
Level 10
Orono, ME

@Ann72 Ugh, since "verifying" my phone number this morning I am no longer getting Airbnb text notifications 😞

 

 

 

You're kidding me @Emilia42.  Seriously is their technology that lame that they either can't verify you, or when they do verify you, disable something else that worked perfectly?

@Ann72 

That seems to be the case! Arg! When I go to my notification settings and try to click on my phone number to schedule notifications I get this message:

 

Screen Shot 2022-04-18 at 4.22.38 PM.png

OH. MY. GOD @Emilia42 !!!!  

 

I would change all the notifications in my account, turn my phone off, then turn it back on and change them back.

 

After that -  @Stephanie help!!!!

@Emilia42 @Ann72 

I'm also  no longer getting text messages from ABB today either after additional reccomened yearly verification process last night. 

When checking settings for Notifications, It also says it "failed to update" when selecting the only phone number for my account.  

 

@John5097 @Ann72 Ah! I logged out and logged back in with my phone so I received the SMS "access code" to get into my account. But no notifications of bookings or guest messages.

 

@Stephanie If you could help, that would be wonderful! I am missing vital messages from guests

@Emilia42 

Try refreshing your notifications settings page again. I did and was able to select phone number without getting the fail to update  error message, and a little check mark. I'll know tomorrow if I'm getting text messages again. 

@Ann72 @Stephanie 

@John5097 @Ann72 

Yay! This morning my telephone number has populated the box and I just got a notification a minute ago 🙂 I did contact support and they told me the system takes about 2 hours to update. This took a lot longer than 2 hours but at least it is working now. 

 

@Stephanie

You can stand down 🙂 The panic is over! 

Aileen110
Level 2
Galashiels, United Kingdom

As someone whose account was hacked twice in a week with numerous fraudulent listings and fraudulent and real bookings for these and with little to no help from Airbnb, this article I hope will help others to not go through the same experience. I do feel Airbnb should be encouraging us all to make our accounts more secure, however I could barely get them to answer the phone and had to work out myself how to get myself out this awful situation. 

 It was odd, just one day my language turned to Spanish and then my payout bank account was changed.  I filed a customer support issue and they said that my Airbnb account was hacked and that they got my email as well.  They  also got my SS# and DOB.  They applied for a loan and 5 credit cards with this information.  I am now battling identity fraud.  I found out yesterday that they did a forward on my mail to another address.  I was very disappointed with AirBNB's response.  They were very  nonchalant about the whole issue.  They told me to change my password to something less personal.  WTF? I am still concerned about the security and the fact that they have not let us know that their system was in fact hacked. 

Anyone else with similar issues?

We were just hacked yesterday and I wanted to warn the community of the technique

 

they got in and first changed the language to Chinese. So that when the “did you change your email address?” warning came out I deleted it as bogus

 

Then when we couldn’t log in, we found the email - translated it! - and were able to follow the restoration process to some success

 

then the hackers tried again by logging in through google account. We got it back. I think we have them locked out, but I don’t know what I don’t know. 

i also worry about their endgame. My payment methods are intact. But this thread warned of DOB and SSN access???  What else might be at risk?