This article contains:

Subscribe to The Duve Blog

Stay updated on the latest Guest Experience and Hospitality Tech updates.

A guest receives a message asking them to confirm their payment details before arrival. It appears to come from your property and urges them to act quickly to keep their reservation. They contact the front desk to check whether it’s legitimate.

How your team responds matters. Recognising suspicious messages, helping guests verify requests, and securing the systems your property uses can help prevent a phishing attempt from becoming a larger issue.

Understand where suspicious messages can come from

Hotels work with several systems to manage reservations, payments, email, and guest communication. Attackers may impersonate one of these providers or use a compromised account in a third-party service to make a fraudulent request appear legitimate.

A message that references your hotel or a familiar platform does not, on its own, establish where the attempt originated or indicate that Duve has been compromised. Identifying the source requires reviewing the message and relevant account activity.

The practical starting point is to protect access across your connected systems, including company email and third-party vendor accounts.

Help guests verify unexpected requests

Make it easy for guests to know how your property communicates and where they should complete payments. Explain which official hotel or booking channels you use, and encourage guests to contact your team through a known phone number or previously verified channel if a request seems unusual.

Unexpected requests to pay again, provide card details, or act immediately to avoid cancellation should prompt a check before the guest proceeds. Guests should avoid replying to suspicious messages or using the links and contact details within them to verify the request.

Your reservations and front desk teams should give consistent guidance so guests receive a clear answer, regardless of who handles the enquiry.

Protect the accounts behind your guest communication

Each employee should have an individual Duve account with a unique password and only the permissions their role requires. Shared credentials make it harder to manage access and identify who performed an action. Remove access when someone leaves and review permissions when responsibilities change.

Keep multi-factor authentication (MFA) enabled for every user. Each person should use their own authenticator app and never share verification codes or approve unexpected authentication requests. In Duve, MFA can be configured under User Profile → MFA.

Apply the same care to your company email accounts. Email may receive password reset links and security notifications, making it an important part of protecting access to other systems.

Use the security controls available in Duve

Enable Link SafeGuard under Settings → Advanced Settings → Security. This adds protection by helping prevent incoming hyperlinks from external sources from being accessed directly inside Duve.

Regularly review Settings → Users & Permissions and Settings → Connections to check who has access and which integrations are connected. Keep only approved connections that your property needs. Some settings require administrator access.

On shared reception computers and tablets, each employee should sign in with their own account, log out after use, and lock the device when stepping away. Keep browsers and operating systems updated.

Act promptly when something looks wrong

If a guest or colleague reports a suspicious message, avoid clicking its links or replying. Check the sender’s full email address and the website address behind any request, rather than relying on a familiar name or logo.

If you entered your credentials on a suspicious website, change the affected password immediately through the service’s official website. For concerns involving your Duve account, open Duve through your saved bookmark and contact Duve Support for help reviewing account activity. Report suspected phishing to your email provider and involve the relevant third-party provider where appropriate.

Duve will never ask you to share your password or MFA verification codes. Treat any message requesting those credentials as suspicious.

Clear guest guidance and consistent account security practices help your team respond quickly and protect the trust guests place in your property. For help reviewing your Duve security setup, contact Duve Support.

whatsapp facebook linkedin twitter email
About the author

The Duve team comprises hospitality experts specializing in guest experience personalization, operational optimization, and innovative hotel technologies. With deep industry knowledge, they help hospitality providers elevate service, enhance satisfaction, and drive growth.

You may also like

Jul 30, 2026   •   5 min. read
Duve Integrates with Expedia Group
Jul 06, 2026   •   4 min. read
How to Scale the Guest Experience Across Hotel Groups