Account security!

Chris11645
Level 1
London, GB

Account security!

Hi there,

 

2 weeks ago I started receiving emails in Chinese from Airbnb. I thought they were spam so I deleted these emails.

 

I checked again a few days ago and found some more Airbnb emails in Chinese. I logged onto my Airbnb account on my phone and it appeared as thought someone had simply logged on, changed my name and booked a holiday on my account. My old photos were still on the account and other personal information including my date of birth.

 

Strangely this person had paid for the trip themselves and I was not charged.

 

I reported this to Airbnb and have subsequently changed my passwords to almost all of my various internet accounts. I was told that the security team would investigate this further. They cancelled the trip and the booked holiday was refunded to whatever account was used to pay for it.

 

I received a text message from my old phone number that I used years ago from the person who has apparently booked this holiday and logged into my account. They had explained to me that they had my old number through EE who do indeed recycle old numbers that aren't used for years. She mentioned that she had managed to login to my Airbnb account via a Chinese version of Whasapp called WeChat using my old number.

 

She had gained access to my new phone number via Airbnb and she explained that she was able to login to my account. She was concerned about her refund. I was extremely concerned about this and why she had been able to access my new number even after changing passwords, but it is clear that changing passwords hasn't removed access for this other person.

 

I explained that she needed to contact Airbnb and EE asap and leave it to Airbnb. However, the fact that I changed passwords does not seem to have made a difference as I was receiving notifications that someone had logged in again and my account had been locked as a result.

 

I have contacted Airbnb this morning again and requested to speak with the security team because I am extremely worried about the safety of my personal data. I received generic support emails that gave no indication of the actual issue. Apparently I cannot speak to anyone in the security department about this because they do not have a phone number.

 

If this is accurate it would seem that Airbnb have a serious security vulnerability with people using old phone numbers to login to Airbnb via this Chinese Wechat app (if that is even accurate). I am unhappy with the level of support from Airbnb considering that a lot of personal data is on here. I am extremely concerned about the safety and security of my data and am wondering whether this has happened to anyone else?

 

At this point in time and with the lack of clarity or communication from Airbnb I am tempted to completely remove my Airbnb account because it seems there is a vulnerability that has not been resolved.

 

As I said, all my passwords have now changed but it is still very worrying!

 

Regards.

Chris

 

3 Replies 3
Helen427
Level 10
Auckland, New Zealand

@Fraser22is this something you can help @Chris11645  with?

 

Thanks in advance.

Dean608
Level 1
Brookfield, IL

I received a verification code I did not request

MikeAndDebbie0
Level 2
Gambrills, MD

My account where my earnings are deposit has been changed twice due to hacking.