Multi-factor authentication will soon be required for every Preno user

Cybercriminals are increasingly targeting accommodation businesses to steal login details, access genuine reservation information and send convincing scams to guests.

These attacks are not limited to large hotel chains. Independent hotels, motels, guesthouses and holiday rentals around the world have been affected.

That is why, from September 2026, everyone using Preno will need to have multi-factor authentication, or MFA, enabled.

We know MFA adds an extra step to signing in. We are making this change because a password on its own no longer provides enough protection for the guest and business information held in accommodation systems.

We are also introducing easier account recovery options and preparing to release passkeys, which will provide a faster way to sign in securely.

Why this matters for accommodation businesses

Accommodation businesses hold information that is particularly useful to scammers, including guest names, contact details, stay dates and reservation information.

Attackers often begin by targeting the people working at a property. A fake email that appears to be from a booking platform can lead an employee to enter their login details or download malicious software. Once criminals have access to genuine booking information, they can send guests highly convincing requests to confirm a payment or provide their card details.

Recent examples show how widespread these attacks have become:

  • Security company Norton identified reservation-hijacking scams involving information from more than 350 hotels, motels, guesthouses and holiday rentals across 50 countries, according to WIRED’s reporting on the campaign.
  • Microsoft identified a phishing campaign impersonating Booking.com and targeting hospitality organisations across Europe, North America, Oceania and Asia. The campaign was designed to steal employee credentials and install malware.
  • ABC News reported on Australian travellers receiving fraudulent messages containing accurate information about their reservations, making the requests appear to have come from the property or booking platform.

These examples matter because a stolen password can be the first step that gives an attacker access to a business account.

MFA adds another identity check when someone signs in. Even if a password is stolen, the attacker should not be able to access the account using that password alone.

What you need to do

Before MFA becomes mandatory in your region:

  1. Set up MFA on your own Preno login.
  2. Check that the list of users is current, and remove access for anyone who no longer works with you.
  3. Ask anyone who has not yet enabled MFA to complete their setup before the deadline.

👉 Follow our step-by-step MFA setup guide and be ready for the September deadline.

Every team member should ideally have their own Preno login. This makes it easier to manage access when someone joins or leaves and provides a clearer record of activity within Preno.

Several people can continue using Preno from the same reception computer or shared device. They should sign in using their own user accounts rather than sharing one login.

Passkeys are coming soon

We are preparing to introduce passkeys as another way to sign in.

A passkey uses the security already built into your phone or computer, such as a fingerprint, face scan or device PIN. This will give users who prefer it a faster, phishing-resistant way to access Preno without entering a password and authentication code during everyday sign-in.

You will need to establish MFA first. Once passkeys are available, you will be able to add one as a more convenient sign-in method.

We will share instructions when passkeys are released.

We have also introduced backup codes, which provide a secure way to regain access if your usual authentication device is lost, replaced or unavailable. You can save these somewhere secure and generate a new set from within Preno when needed.

When will MFA become mandatory?

We are introducing the requirement gradually by country so we can support customers through the change and apply what we learn during each stage of the rollout.

MFA will become mandatory on:

  • 1 September 2026 for New Zealand
  • 8 September 2026 for Australia
  • 15 September 2026 for the United Kingdom and the rest of the world

We will send reminders by email and inside Preno before the deadline for each region. Users who have already completed setup will not need to take any further action.

Setting it up now is the best way to make sure you and your team can continue accessing Preno without interruption.

Frequently asked questions

What do I need to do?

Before the deadline for your region:

  1. Set up MFA on your own Preno login.
  2. Check that current team members each have the Preno access they need, and remove access for anyone who no longer works with you.
  3. Ask anyone who has not yet enabled MFA to complete their setup.

Why are you making MFA mandatory?

Passwords can be stolen through phishing, reused across different websites or exposed in an unrelated data breach.

MFA adds another identity check when someone signs in. This means that even if a password is stolen, it should not be enough on its own to access the Preno account.

Requiring MFA for every user helps protect your property’s operations, guest information and business reputation.

Is this really necessary for a small property?

Yes. Reservation scams and phishing attacks are not limited to large hotel chains.

Independent hotels, motels, guesthouses and holiday rentals around the world have been affected. Smaller properties can also be attractive targets because they often have lean teams, shared responsibilities and less dedicated cybersecurity support.

Will I need to use MFA every time I access Preno?

Not every time you open or use Preno. However, you will be asked to verify your identity periodically as part of keeping your account secure.

We will continue to balance strong protection with making everyday access as straightforward as possible.

What happens if I lose or replace my authentication device?

You can use one of your saved backup codes to regain access to your account.

Once signed in, you can update your authentication method and generate a new set of backup codes. Keep these codes somewhere secure and separate from the device you normally use to authenticate.

If you don’t have access to your backup codes, ask your team member with user management permissions to help you regain access through your account recovery settings.

What happens if our team shares a login?

We strongly recommend giving each person their own Preno login rather than sharing one.

Individual logins are more secure, make it easier to remove access when someone leaves and provide a clearer record of who completed actions within Preno. Preno usernames do not need to have a unique email address. 

Some email providers also support aliases using a plus sign. For example, [email protected] and [email protected] may both deliver emails to [email protected] while allowing separate usernames to be created. Check that your email provider supports this before using this approach.

What happens if several team members use the same computer or tablet?

Sharing a device is different from sharing a login.

Several people can continue using Preno from the same reception computer or tablet, but each person should sign in with their own Preno user account.

Shared devices should be locked when unattended, and users should sign out when they have finished if other people can access the device.

What is the difference between MFA and a passkey?

MFA verifies your identity in more than one way. You sign in with your password, then confirm your identity using a code from an authenticator app on your phone. You can also use backup codes as a backup if you lose access to your app.

A passkey lets you sign in using the security built into your phone, computer or password manager, such as a fingerprint, face scan or device PIN.

Passkeys are designed to provide a faster everyday sign-in experience while offering strong protection against phishing.

Do I need to set up both MFA and a passkey?

You will need to set up MFA before the deadline for your region.

Passkeys will be an optional additional sign-in method when they become available. After establishing MFA, you will be able to add a passkey for a faster way to sign in.

How do I set up a passkey?

Passkeys are coming soon.

We will update this article and provide step-by-step instructions when they are available.

When will MFA become mandatory?

MFA will become mandatory on:

  • 1 September 2026 for New Zealand
  • 8 September 2026 for Australia
  • 15 September 2026 for the United Kingdom and the rest of the world

We will remind users by email and inside Preno before the deadline for their region.

Where can I get help?

Our Support team can help if you have trouble setting up MFA or recovering access to your account.

Before contacting Support, check whether you have a saved backup code you can use to sign in. You can also ask a team member with user management permissions to help you regain access through your account recovery settings.

About the author

Kevin is Preno’s Chief Product Officer and has spent nearly a decade helping shape Preno’s product. He enjoys translating ideas from other industries into simple, intuitive tools for independent hoteliers — products that just work, so users don’t have to think about them.