Ecommerce For Tourism HospitalityUnit 68 min read
E-Commerce Security, Fraud Prevention & Data Protection in Tourism
Unit 6 of Ecommerce For Tourism Hospitality covers cybersecurity threats in online tourism bookings, fraud detection techniques, data protection laws (GDPR, PDPA), encryption methods, and real-world case studies like Daraz scams and Ncell payment frauds—with visuals of attack vectors, secure payment flows, and complian
Core Concepts & Definitions
1. E-Commerce Security: The Foundation
E-commerce security in tourism and hospitality refers to the protection of digital transactions, guest data, and operational systems from cyber threats. Unlike traditional bookings, online systems handle sensitive data (credit cards, PII) and are prime targets for fraudsters.
Key Threats:
- Phishing: Fake hotel booking sites (e.g., "HotelX.com" vs. "HotelX-Nepal.com").
- Credit Card Fraud: Stolen card details used for reservations (common in Daraz/Ncell bookings).
- Data Leaks: Unauthorized access to guest records (e.g., 2021 NTC customer data breach).
- DDoS Attacks: Overloading hotel websites during peak seasons (e.g., Dashain/Tihar bookings).
2. Fraud Prevention Techniques
Fraudsters exploit weak links in the booking chain. Hotels use multi-layered defenses:
| Technique | How It Works | Example in Nepal |
|---|---|---|
| 3D Secure (3DS) | Adds a password step for card payments (reduces card-not-present fraud). | Ncell’s "SecurePay" for online transactions. |
| Tokenization | Replaces card numbers with unique tokens (e.g., Visa Token Service). | Khalti’s "Pay with Token" for repeat users. |
| AI-Based Monitoring | Flags suspicious bookings (e.g., same IP, multiple failed attempts). | Daraz’s fraud detection for fake reviews. |
| Manual Reviews | Staff verify high-risk bookings (e.g., bulk reservations). | Hotel management checking Pathao driver IDs. |
Worked Example: Daraz Scam Detection
- Scenario: A user books a hotel via Daraz but cancels last-minute, keeping the advance payment.
- Fraud Signal: AI detects:
- Same email/IP used for 5 cancellations in 24 hours.
- Payment made via a burner phone number (no KYC).
- Action: Daraz freezes funds and alerts the hotel.
3. Data Protection Laws & Compliance
Hotels must comply with local and international laws to avoid fines or reputational damage.
Real-World Tie-In: Ncell’s Data Breach (2021)
- Issue: Hackers accessed 10M+ customer records (names, phone numbers, transaction history).
- Violation: Failed to encrypt data at rest (PDPA requirement).
- Lesson: Hotels using Ncell for payments must enable end-to-end encryption (E2EE).
4. Secure Payment Gateways
Payment gateways are the highest-risk area for fraud. Hotels use:
| Gateway | Security Feature | Used By |
|---|---|---|
| Khalti | PCI DSS Level 1, 2FA, OTP verification | Most Nepali hotels |
| eSewa | Bank-level encryption, real-time fraud checks | Luxury hotels (e.g., Radisson) |
| PayPal | Buyer/Seller protection, chargeback defense | International chains |
| Stripe | Radar fraud detection, tokenization | Boutique hotels (e.g., Seracap) |
Worked Example: Radisson’s Secure Checkout
- Guest books via Radisson’s website → redirected to eSewa’s PCI-compliant page.
- eSewa generates a one-time token (not stored).
- Hotel database only sees:
Token_12345(not the card number). - If fraud occurs, eSewa reverses the charge within 24 hours.
5. Emerging Trends in Security
| Trend | How It’s Used | Example |
|---|---|---|
| Blockchain | Immutable booking records (prevents cancellations without consent). | Winding Tree (decentralized travel) |
| Biometric Auth | Fingerprint/face ID for check-ins (reduces fake identities). | Marriott’s app-based check-in |
| Zero-Trust Architecture | No default trust; verify every access request (even internal staff). | Google’s BeyondCorp model |
| Quantum Cryptography | Future-proof encryption (resistant to quantum hacking). | Being tested by NTC for critical infrastructure. |
In the Real World
- Pathao’s Driver Verification
- Idea Used: Biometric + KYC fraud prevention.
- How: Drivers submit government ID + selfie for facial matching. Hotels using Pathao for transport cross-check driver IDs to avoid fake bookings.
NEPSE’s Investor Protection
- Idea Used: Two-Factor Authentication (2FA) + Encryption.
- How: Investors must enable OTP + fingerprint to trade shares. If a hacker steals login details, they can’t proceed without the second factor.
Khalti’s "SafePay" for Hotels
- Idea Used: Tokenization + Real-Time Fraud Alerts.
- How: When a guest books a room at Hotel Everest View, Khalti replaces their card number with a token. If the same token is used for a $500 booking followed by a $5,000 "refund" request, Khalti flags it as fraud.
Exam Tip
How This Unit Is Tested:
- Short Answers (5 marks): Define terms like PCI DSS, phishing, or tokenization. Use bullet points in exams.
- Case Studies (10 marks): Analyze a scenario (e.g., "A guest reports a fake charge on their Khalti after booking a room"). Your answer must:
- Identify the fraud type (e.g., "chargeback fraud").
- Explain how it happened (e.g., "Hotel’s payment gateway lacked 3DS").
- Suggest 3 fixes (e.g., "Enable 3DS, use tokenization, train staff on fraud signals").
- Diagrams (5 marks): Draw a secure payment flow or fraud prevention layers (use the Mermaid example above as a template).
- Comparisons (8 marks): Compare Khalti vs. eSewa security features in a table (like the one above).
Top 3 Exam Traps to Avoid:
- Ignoring Nepal-specific laws (e.g., PDPA). Always mention local compliance (Ncell, Khalti, NTC) when asked about security.
- Overlooking real-world examples. If asked about fraud, name a Nepali company (Daraz, Pathao, Ncell) and describe their system.
- Assuming encryption = full security. Explain multi-layered defenses (e.g., "Encryption + 2FA + AI monitoring").
Key Formula to Remember: Fraud Risk Score (FRS) = (Used by Khalti/Daraz to flag high-risk transactions.)
Based on the TU BTTM syllabus for Ecommerce For Tourism Hospitality (BHM301), unit 6.
Discussion
Loading…