Skip to main content

If you think your account has been compromised

Warning signs of unauthorised access to your Preno account, and what to do first.

Written by Kevin Soo

If you think someone else has got into your Preno account, act quickly — and talk to us. This page covers what to look for and what to do.

Warning signs

Any one of these is worth investigating:

  • Guests contacting you about messages, payment requests or booking changes you didn't send

  • Bookings amended, cancelled or refunded that nobody on your team recognises

  • A user account you didn't create, or permissions that have changed on their own

  • Emails from Preno about password or MFA resets that nobody requested

  • Being signed out unexpectedly, or a password that suddenly stops working

  • A device you don't recognise in the active sessions list on your Profile

  • Stored card details revealed when no one on your team needed them

Your Activity History shows what's been changed in your account and by which user. It's the quickest way to confirm whether something is genuinely unexpected.

What to do

Contact our support team straight away — before you start resetting things. If an attacker has access, a self-service password or MFA reset may not remove them, and it can destroy the evidence we need to work out what happened and what was taken. Message us in chat and tell us you suspect unauthorised access.

While you're waiting to hear from us:

  1. Change your own password, if you can still sign in. This signs you out on every device — including anyone else who was signed in as you.

  2. Check your active sessions on your Profile page and end any you don't recognise.

  3. Check your user list in Settings > User management for accounts you don't recognise, and disable any you're unsure about.

  4. Tell your team not to action any unusual payment or booking requests until this is resolved, and to check their own active sessions.

  5. Don't delete anything. Suspicious emails, messages and booking records all help us establish what happened.

Protecting your guests

The most common goal in these attacks is your guests' money. Someone with access to your bookings can message guests convincingly — they have the real booking reference, the real dates, the real name — and ask them to pay again or re-enter their card details.

If you have reason to think guests have been contacted, let them know as soon as you can that any payment request they've received may not have come from you, and tell them how you will and won't ask for payment. We'll help you work out what to send.

Depending on what's been accessed, you may also have reporting obligations under privacy law in your country. We'll talk you through this — it's not something you need to work out alone.

Afterwards

Once access is secured, a few things will reduce the chance of it happening again:

  • Make sure every person has their own login — shared logins make it impossible to tell who did what

  • Confirm every user has MFA set up

  • Review permissions and remove anything people don't need

  • Remove logins for anyone who has left

If you're not sure whether something is a real problem, ask us anyway. We would much rather look into a false alarm than hear about it a fortnight later.

Related articles

Did this answer your question?