Phishing/Social Engineering of Hotel Guests
A few weeks ago, I checked into a hotel. Minutes after arriving, I got a call. "This is Bob at the front desk. Your credit card didn't go through. Could you confirm the number or provide another card?" It was late and I was tired. Bob offered "No need to come back down, you can give me the info over the phone and I can run it."
I got about half way through providing the info and came to my senses. "Tell you what, Bob, I'll come back down to the front desk."
No surprise, the front desk didn't know any "Bob", and my credit card transaction was fine.
I realized then that someone had a direct phone number to the room (...and there seem to be a lot more rooms with direct lines than in the past) and was just calling continuously, with the understanding that he'd eventually catch someone not long after check-in, making his story believable.
Actually, kind of clever.
One other note: this was Times Square NYC hotel, so there were lots of people not familiar with hotel life and, thus, vulnerable.