An online booking system that has been hacked is a time-sensitive problem. For hospitality businesses in Kerala — resorts, houseboats in Alappuzha, homestays in Wayanad — or any service business with customer data stored online, a compromised booking system exposes customer names, phone numbers, email addresses, booking details, and potentially payment information. What you do in the first few hours determines whether this becomes a manageable incident or a business-threatening crisis. Here is the step-by-step response, written for business owners, not IT specialists.
Step 1: Isolate the Compromised System Immediately
The moment you confirm or strongly suspect a compromise, take the affected system offline. For a website booking system, this means contacting your hosting provider and suspending the site immediately. If you have access to your hosting control panel (cPanel, Plesk), take the site to maintenance mode or temporarily suspend the account. If you cannot do this yourself, call your web developer or hosting support immediately.
Why this matters: every minute the compromised system stays online, the attacker may be downloading more data, installing backdoors for future access, or using your system to send spam or attack other targets. Isolation stops the active damage, even if it temporarily inconveniences your bookings.
Do not "just watch it" to see what the attacker does — this is rarely useful for a small business and increases the legal exposure around your customers' data being continuously accessible to the attacker.
Step 2: Document and Preserve Evidence Before Anything Else
Before restoring, cleaning, or modifying anything: take screenshots of what you are seeing, download a copy of the server access logs if available, and note the exact time you discovered the incident and what triggered the discovery. This documentation is needed for:
Any insurance claim if you have cyber insurance. A police complaint if you choose to file one under the IT Act. A regulatory notification under India's DPDP Act 2023. Legal advice on your obligations. Any forensic investigation afterward.
Many businesses immediately start cleaning or restoring, inadvertently destroying the evidence needed to understand what happened and fulfil their legal obligations. Document first, remediate second.
Step 3: Change All Credentials Immediately — From a Different Device
From a device that was NOT connected to the compromised network during the incident, immediately change:
The hosting control panel password. The database password. The CMS (WordPress/Joomla/custom admin) password. All email accounts associated with the domain. Any third-party accounts connected to the booking system (Razorpay, PayU, Instamojo if integrated). Any cloud storage accounts where booking data was backed up.
Use a different device for this because: if the device you normally use to manage the site was also compromised (via malware), changing passwords from it may expose the new credentials to the same attacker immediately. Change from a phone or a separate computer on a different network if possible.
Step 4: Assess Exactly What Data Was Exposed
Not all compromises are equal. The critical question is: what data did the attacker have access to? Log in to your database (after changing credentials and from a clean device) and check what customer data was stored:
Names and email addresses only: Lower severity — inconvenient but not immediately dangerous for customers.
Phone numbers: Can be used for targeted phishing or SIM swap attacks — moderate severity.
Payment card data: High severity — requires immediate contact with your payment processor (Razorpay support) and possible card cancellation advice to affected customers.
Aadhaar numbers or government IDs: High severity — legally sensitive under the Aadhaar Act and DPDP Act 2023.
Document the scope precisely. This determination drives your notification obligations and the urgency of customer communication.
Step 5: Notify Affected Customers Promptly and Honestly
Customer notification is both a legal obligation under India's DPDP Act 2023 and a trust-preservation action. How you communicate in the first 24–72 hours significantly affects whether customers remain loyal or spread negative word-of-mouth.
Communicate directly: WhatsApp message or email to affected customers is appropriate. State clearly what happened (without speculation about who did it), what data was affected, what steps you are taking to fix it, and what customers should do to protect themselves (e.g., watch for suspicious calls, do not share OTPs). Do not use language that minimises the incident or suggests it is not serious — this backfires significantly if the actual impact becomes apparent later.
Consult a legal advisor before making public statements if the breach involved payment data or government IDs. File an incident report at CERT-In (India's Computer Emergency Response Team, cert-in.org.in) for significant breaches.
Frequently Asked Questions
Do I need to report a data breach to authorities in India?
Under India's DPDP Act 2023, breaches involving personal data of Indian residents require notification to the Data Protection Board of India and affected individuals. Verify current specific timelines with a legal advisor. Payment data breaches also trigger obligations with your payment processor and potentially the RBI. Document the incident timeline and consult legal advice before public statements.
Should I pay a ransom if my booking data is encrypted by ransomware?
No. Paying does not guarantee a working decryption key, does not remove the attacker's backdoor (so you may be reinfected immediately), and funds further criminal operations. Report to CERT-In (cert-in.org.in), check the No More Ransom project (nomoreransom.org) for free decryptors, and restore from a clean backup. This is the correct sequence regardless of ransom demand amount.
How do I know if customer data was stolen versus just encrypted?
In many organised ransomware attacks, data is exfiltrated before encryption as additional leverage. Signs: unusual large outbound transfers in server logs before the encryption; the ransom note explicitly mentions copied data; your business appears on a ransomware group's public leak site. A forensic specialist can analyse server and network logs to determine if exfiltration occurred — important for DPDP Act notification decisions.
How long does it take to recover from a website hack in India?
With a clean, recent backup: 4–24 hours to restore, verify, and close the exploited vulnerability. Without a backup: days to weeks of uncertain forensic cleanup. This is why off-server daily automated backups are the single most important recovery investment. Restore from backup + close the vulnerability + bring back online is always faster than manual cleanup.