Summary
- In all cases reported to us, unauthorized access to the conference system could be ruled out.
- Contact details were gathered from publicly available sources.
- Warn participants early about fraudulent contacts; this is the most effective protection.
- Participants do not need to change their ConfTool passwords.
|
Is this a data breach?Almost certainly not. We have been hearing about incidents like this several times a year for more than ten years, and in every case reported to us we have been able to rule out unauthorized access to the ConfTool installation.
However, that does not mean the data came from somewhere unrelated to your event. Conference participation is public by nature: programs, abstracts and proceedings are published, and the contact details of academic participants are usually freely available on institutional websites. Fraudsters compile their lists from these sources.
Your own published program is often the most convenient source of all. ConfTool can generate and publish your agenda and a list of participants, and
if you make this information
openly accessible rather than
restricting it to registered participants until the conference, it presents names, organizations and session details together on a structured page. That is considerably easier to collect automatically than the same information scattered across a dozen websites, and it noticeably increases the risk. Restricting access to registered — or already paying — participants reduces it.
It does not remove the risk entirely: programs are frequently published as PDFs on the conference website, abstracts appear in proceedings, and speaker pages remain online regardless. It is therefore worth checking what is publicly visible for your own event. Search for your conference name together with a few speaker names and see what a stranger would find.
Many organizers publish their program deliberately, because it helps promote the event and participants expect it. That is a legitimate trade-off rather than a mistake — it simply makes the warning described below all the more worthwhile.
Warn your participants before they are contacted by fraudstersWarning your participants is the single most effective countermeasure, and it works far better as a precaution than as a reaction. Participants who have been told what to expect are much less likely to respond.
We suggest sending a short note twice:
when you publish your program, which is when the scraping typically begins, and
shortly before the event, when the accommodation scam is most active.
You are welcome to adapt the following text:
Please be aware that third parties unconnected with this conference may contact you by e-mail or telephone, often claiming to arrange your accommodation or registration. They may ask for credit card details or other personal information.
The organizers will never ask you for payment details by e-mail or telephone. All registration and payment for this conference takes place exclusively through our official conference system. If you are contacted in any other way, please do not respond, and let us know.
|
Please also include your own contact details, so that participants can ask questions or report that they have been targeted.
If someone has already given out payment detailsAdvise them to act immediately:
- Contact their bank or card issuer at once and have the card blocked.
- Let you as the organizer know, so that you can warn the remaining participants.
- Report the incident to the police. In some countries, consumer protection agencies also collect such reports.
Speed matters far more than certainty here. It is better to block a card unnecessarily than to wait for confirmation that the call was fraudulent.
Do participants need to change their ConfTool passwords?No. There is no benefit in asking them to.
ConfTool does not store passwords in a recoverable form. Passwords are kept as salted cryptographic hashes, which means that even someone with full access to the database cannot recover the original passwords.
If you still suspect unauthorized access to your installationIf something else makes you think your installation has been accessed, you can review all user activity yourself:
Overview → Browse System LogThe page offers a range of filtering options (see the attached screenshot). If you find anything you consider suspicious, please contact us.
Should a conference account genuinely be compromised, the most common cause is not the conference system but an infected computer belonging to an organizer or assistant — malware that captures keystrokes and locally stored credentials would give an attacker access to that person's account.
To reduce this risk:
- Always keep your operating system and applications up to date.
- Use an ad and script blocker such as uBlock Origin.
- Do not open attachments or follow links in unsolicited e-mails.
- Use a password manager in your browser. It compares the URL of the website you are visiting with the stored account data and will not enter your password on a phishing site.
Be especially wary of unexpected messages that appear to come from your e-mail administrator or that link to documents you were not expecting.
Company names reported to usThe names change regularly, so treat the pattern as the reliable signal rather than any particular name. Typically, these organisations present themselves as a travel, housing or registration service, claim to be handling your hotel booking, and create a sense of urgency before asking for card details. In the events industry they are commonly referred to as
housing pirates or
room poachers — useful terms if you want to search for further warnings.
Names that organizers have reported to us, or that appear in published warnings from other institutions:
- Elite Housing Service
- Exhibitor Housing Services (EHS)
- Exhibitor Housing Management (EHM)
- Expo Hotel Services
- Global Travel, Global Travel Team, Global Travel Experts, Global Travel Management
- Operations Global
- Travel Housing Team (THT)
- Traveller Point (TP)
We have not independently verified these reports; we list them because they are the names participants are likely to search for after being contacted.
Have you encountered a name that is not listed here? Please
send a short e-mail. Keeping the list current helps other organizers recognize the pattern early.
Scam targeting exhibitors and sponsorsA related scam targets exhibitors and sponsors rather than participants: fraudsters offer to sell the conference's attendee list, falsely claiming to represent the organizers. Again, they either compile these lists from public sources or just assemble fake addresses. If your event has industry participation, it is worth adding a clear statement to your website that you do not publish, sell or rent participant data — this gives exhibitors the same simple test that the e-mail template above gives participants.
Further reading| Conclusion: this is not a ConfTool-specific problem. Conferences using other systems are targeted in the same way, for the same reason: program data is often public. |