Skip to main content
ThreatScams & fraud

Fake Airbnb host payout-hold lure — "payout held due to guest complaint / KYC re-verification / policy review, verify within 24 hours or listing delisted" targeting 5M+ Airbnb hosts; host credentials + 2FA + bank routing harvest enables payout redirect, listing hijack (attacker relists under trusted-reputation account), reservation-fee extraction, past-guest PII exfil

fake-airbnb-host-payout-hold-lure

What this tier means

High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.

How Gorganizer detects this

Fake "your Airbnb payout has been placed on hold due to a guest complaint / KYC re-verification / policy review — verify within 24 hours or the payout will be canceled and your listing will be delisted" email targeting Airbnb's 5M+ host base. Harvests host credentials, 2FA, and bank routing. Post-compromise attackers: (1) redirect the Airbnb payout to attacker-controlled bank accounts; (2) delist the real listing and relist attacker-controlled ones under the same trusted-reputation host account, gaining the review history of a legitimate operator; (3) exfil message history with past guests (guest PII for credential-stuffing downstream); (4) hijack upcoming reservations to extract guest cancellation fees or scam upcoming arrivals. The lure converts because Airbnb genuinely DOES place payouts on hold for real compliance and dispute reasons — chargebacks, guest disputes, KYC re-verification. Hosts are primed because payout holds are common and lost payout equals lost cash flow. Airbnb's own security advisory plus travel outlets (The Points Guy, Skift) documented sustained 2024-2025 campaigns. Fires when body references Airbnb / Airbnb host / Airbnb listing / Superhost / host payout / Airbnb reservation AND contains payout-hold / guest-complaint / listing-delist / KYC-re-verification / verify urgency. Excludes airbnb.com (+.co.uk, .de, .fr, .it, .es, .com.au, .se) and airbnbmail.com. Auto-classified as danger via the `-lure` suffix.

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started