BHM301 Ecommerce For Tourism Hospitality

Ecommerce For Tourism HospitalityUnit 68 min read

E-Commerce Security, Fraud Prevention & Data Protection in Tourism

Unit 6 of Ecommerce For Tourism Hospitality covers cybersecurity threats in online tourism bookings, fraud detection techniques, data protection laws (GDPR, PDPA), encryption methods, and real-world case studies like Daraz scams and Ncell payment frauds—with visuals of attack vectors, secure payment flows, and complian

Core Concepts & Definitions

1. E-Commerce Security: The Foundation

E-commerce security in tourism and hospitality refers to the protection of digital transactions, guest data, and operational systems from cyber threats. Unlike traditional bookings, online systems handle sensitive data (credit cards, PII) and are prime targets for fraudsters.

→ DataPayment Gateway🔒 Encryption📜 PCI DSS Compliance→ PaymentHotel Website🔐 2FA→ BookingGuestE-Commerce Security Flow in Tourism
Flow of guest data and security measures in e-commerce transactions (Nepal context)

Key Threats:

  • Phishing: Fake hotel booking sites (e.g., "HotelX.com" vs. "HotelX-Nepal.com").
  • Credit Card Fraud: Stolen card details used for reservations (common in Daraz/Ncell bookings).
  • Data Leaks: Unauthorized access to guest records (e.g., 2021 NTC customer data breach).
  • DDoS Attacks: Overloading hotel websites during peak seasons (e.g., Dashain/Tihar bookings).

2. Fraud Prevention Techniques

Fraudsters exploit weak links in the booking chain. Hotels use multi-layered defenses:

Phishing Attacks (35%)Credit Card Fraud (25%)Identity Theft (20%)Fake Bookings (15%)Other (5%)
Top fraud types in Nepalese tourism e-commerce (2023 data)
Technique How It Works Example in Nepal
3D Secure (3DS) Adds a password step for card payments (reduces card-not-present fraud). Ncell’s "SecurePay" for online transactions.
Tokenization Replaces card numbers with unique tokens (e.g., Visa Token Service). Khalti’s "Pay with Token" for repeat users.
AI-Based Monitoring Flags suspicious bookings (e.g., same IP, multiple failed attempts). Daraz’s fraud detection for fake reviews.
Manual Reviews Staff verify high-risk bookings (e.g., bulk reservations). Hotel management checking Pathao driver IDs.

Worked Example: Daraz Scam Detection

  • Scenario: A user books a hotel via Daraz but cancels last-minute, keeping the advance payment.
  • Fraud Signal: AI detects:
    • Same email/IP used for 5 cancellations in 24 hours.
    • Payment made via a burner phone number (no KYC).
  • Action: Daraz freezes funds and alerts the hotel.

3. Data Protection Laws & Compliance

Hotels must comply with local and international laws to avoid fines or reputational damage.

2018 AD (2075 BS)GDPR Enacted (EU)– Applies to hotels wi2020 AD (2077 BS)PDPA (Nepal) –Mandates data localizaOngoingPCI DSS –Encryption and audits
Key data protection laws timeline for tourism e-commerce in Nepal

Real-World Tie-In: Ncell’s Data Breach (2021)

  • Issue: Hackers accessed 10M+ customer records (names, phone numbers, transaction history).
  • Violation: Failed to encrypt data at rest (PDPA requirement).
  • Lesson: Hotels using Ncell for payments must enable end-to-end encryption (E2EE).

4. Secure Payment Gateways

Payment gateways are the highest-risk area for fraud. Hotels use:

Gateway Security Feature Used By
Khalti PCI DSS Level 1, 2FA, OTP verification Most Nepali hotels
eSewa Bank-level encryption, real-time fraud checks Luxury hotels (e.g., Radisson)
PayPal Buyer/Seller protection, chargeback defense International chains
Stripe Radar fraud detection, tokenization Boutique hotels (e.g., Seracap)

Worked Example: Radisson’s Secure Checkout

  1. Guest books via Radisson’s website → redirected to eSewa’s PCI-compliant page.
  2. eSewa generates a one-time token (not stored).
  3. Hotel database only sees: Token_12345 (not the card number).
  4. If fraud occurs, eSewa reverses the charge within 24 hours.

Trend How It’s Used Example
Blockchain Immutable booking records (prevents cancellations without consent). Winding Tree (decentralized travel)
Biometric Auth Fingerprint/face ID for check-ins (reduces fake identities). Marriott’s app-based check-in
Zero-Trust Architecture No default trust; verify every access request (even internal staff). Google’s BeyondCorp model
Quantum Cryptography Future-proof encryption (resistant to quantum hacking). Being tested by NTC for critical infrastructure.

In the Real World

  1. Pathao’s Driver Verification
    • Idea Used: Biometric + KYC fraud prevention.
    • How: Drivers submit government ID + selfie for facial matching. Hotels using Pathao for transport cross-check driver IDs to avoid fake bookings.
Cause: Unencrypted guest databaseImpact: 500+ records exposedSolution: Implemented 2FA + PCI DSS2022: Hotel X Data BreachReal-World Security Incident
Case study: How a Nepali hotel recovered from a breach
  1. NEPSE’s Investor Protection

    • Idea Used: Two-Factor Authentication (2FA) + Encryption.
    • How: Investors must enable OTP + fingerprint to trade shares. If a hacker steals login details, they can’t proceed without the second factor.
  2. Khalti’s "SafePay" for Hotels

    • Idea Used: Tokenization + Real-Time Fraud Alerts.
    • How: When a guest books a room at Hotel Everest View, Khalti replaces their card number with a token. If the same token is used for a $500 booking followed by a $5,000 "refund" request, Khalti flags it as fraud.

Exam Tip

How This Unit Is Tested:

  • Short Answers (5 marks): Define terms like PCI DSS, phishing, or tokenization. Use bullet points in exams.
  • Case Studies (10 marks): Analyze a scenario (e.g., "A guest reports a fake charge on their Khalti after booking a room"). Your answer must:
    1. Identify the fraud type (e.g., "chargeback fraud").
    2. Explain how it happened (e.g., "Hotel’s payment gateway lacked 3DS").
    3. Suggest 3 fixes (e.g., "Enable 3DS, use tokenization, train staff on fraud signals").
  • Diagrams (5 marks): Draw a secure payment flow or fraud prevention layers (use the Mermaid example above as a template).
  • Comparisons (8 marks): Compare Khalti vs. eSewa security features in a table (like the one above).

Top 3 Exam Traps to Avoid:

  1. Ignoring Nepal-specific laws (e.g., PDPA). Always mention local compliance (Ncell, Khalti, NTC) when asked about security.
  2. Overlooking real-world examples. If asked about fraud, name a Nepali company (Daraz, Pathao, Ncell) and describe their system.
  3. Assuming encryption = full security. Explain multi-layered defenses (e.g., "Encryption + 2FA + AI monitoring").

Key Formula to Remember: Fraud Risk Score (FRS) = (Used by Khalti/Daraz to flag high-risk transactions.)

Based on the TU BTTM syllabus for Ecommerce For Tourism Hospitality (BHM301), unit 6.

Discussion

Loading…