Booking.com hacked and scammers using data to scam customers

Brendan Burgess

Founder
Messages
58,309

A data breach at travel giant Booking.com is leading to a fresh wave of scams recently dubbed "reservation hijacks".

Hackers stole customer data that experts say could lead to a surge in the scams as customers are tricked into sending criminals money.

Some customers have contacted the BBC to say they have already started receiving suspicious messages.

A friend of mine got this just now via What's App.


Hello, [recipient's name redacted]
My name is Linda.
I am the administrator of Clayton Hotel Dublin Airport Your Booking ID [ correct booking number]

My assistant tried to contact you today regarding your reservation from 25.05.2026 to 26.05.2026

During a recent automatic security check, our payment system was unable to verify your card details.

As part of Booking's new policy to improve booking security, some guests are now required to confirm that they are the cardholder and that their booking is legitimate.

Please complete a short verification process to prevent your booking from being canceled.

[scam website redacted]

That's why I'm reaching out to you personally to quickly and easily resolve this issue.

Please take this seriously and do so within the next 12 hours, otherwise your reservation may be canceled and your dates will be available for booking by other guest
 
Last edited:
We have heard in the past the scammers do it by compromising the hotel's admin account on booking.com, which suggests poor password protection, but we have also heard that 2FA was introduced which should prevent this. The fact that multiple people at a hotel are likely to use their admin account makes this a weak point from a security POV.
For a long time the compromise path was through the hotels and their staff accounts but as per post #118, Booking.com have recently disclosed a successful attack on their systems too.

Attacking the hotel staff is usually easier as they are less likely to be trained to recognise scams and a very much customer service focused. Booking.com allow multiple user and administrator accounts each with different MFA, but it's likely mane hotels are keeping it simple and sharing accounts across multiple staff.

Ideally hotels should use separate accounts for Booking.com and other such platforms that are not tied to staff member accounts or email addresses. Reusing staff daily use accounts increases the risk of exposure through someone clicking on a phishing link.
 
Booking.com have recently disclosed a successful attack on their systems too.
I found this from a week ago: https://www.techzine.eu/news/securi...ta-breach-remains-tight-lipped-about-details/

On the 14th I got an email from booking.com which in hindsight was obviously triggered by this breach.
We recently noticed suspicious activity affecting a number of reservations and we immediately took action to contain the issue.

In the course of that article it refers to a previous breach in 2018. I'm glad to see they got a substantial fine under GDPR.
The Booking.com platform is no stranger to attempted attacks. Sometimes this has led to data breaches. In 2018, for example, criminals used phishing to steal login credentials from hotel employees in the United Arab Emirates, thereby gaining access to booking data for over 4,000 customers. At the time, Booking.com reported the breach to the Dutch Data Protection Authority 22 days late—far too late to meet the 72-hour requirement under the GDPR. This resulted in a fine of 475,000 euros from the privacy watchdog.
 
In an earlier reply in this thread I mentioned that I recently received an email from booking.com which referred to a data breach.

A few days later I happened to receive an email fom Intersport Germany (I used to spend time there) about a data breach.
It's interesting to compare the two emails.

The Booking.com email is titled "Important Booking.com Security Update".
The Intersport email in translation is titled "Reporting a personal data breach".
The Intersport email goes into much greater more detail about what was affected and the consumers rights under GDPR.
I attach both.
 

Attachments

From the newstalk.com article:
However, a few weeks later, the platform’s website was hacked and some people’s details were illicitly obtained.

Booking.com contacted customers to warn them of the data breach but Ms King didn’t pay much attention to the email at the time.

As I noted earlier in this thread, the email booking.com sent to customers in April was cunningly titled "Important Booking.com Security Update". Easy to ignore.

Booking.com should have reported this to the Dutch data protection organization within 72 hour. It's not possible to know when or whether they did, since that body has not published anything about it.

My friend ChatGPT says:
If Booking.com concluded that the incident was a personal data breach likely to result in a risk to the rights and freedoms of natural persons, then Article 33 GDPR requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

Given that the exposed information reportedly included names, email addresses, phone numbers and booking details—and that Booking.com itself warned customers about the increased phishing risk—it is quite plausible that the threshold for notification was met. However, only Booking.com and the Dutch AP know whether a formal Article 33 notification was made.

One interesting point is that Booking.com has history here: in relation to a 2019 breach, the Dutch AP fined the company €475,000 for reporting the breach 22 days late, well beyond the GDPR's 72-hour requirement. That precedent means the company is likely to have been especially conscious of its notification obligations in 2026
 
I got an email from Quest appartment hotels the other day saying something similar to above with a big long email, wuth rmthe email address ending ..... .com.au - never heard of that type of ending? It said they'd had an ".... unauthorised access to their data base..." and my name and email address had been included. They said also:
The information involved relates to records from before June 2025.

When i searched for 'quest' in my emails a recent booking of an apartment with booking.com was identified.

They went into lengthy details about trying to understand how the breach occurred, and they were undertaking forensic examinations, etc, etc, and warned me to be vigilent.

I Had no spam messages about my booking, which went very smoothly, tho at the last minute i felt i shouldnt have booked with booking.com as i remembered too late about scams with them outluned here on aam.

Not sure what to make of it but definitly wont be using booking.com again
 
I was scammed through booking.com

But now I am alert to it, I am happy enough to use their services.

But if I can book directly with the hotel , I do.
 
I was in Australia in 2024 but did not book any of my accomodation. My email address may have been requested at check in.
 
Just got a scam WhatsApp today for a hotel booked through booking.com weeks ago, so convincing as they had various info of the booking.
 
Just got a scam WhatsApp today for a hotel booked through booking.com weeks ago, so convincing as they had various info of the booking.
Since it's a recent booking, unless booking.com had a new hack on their systems, then likely the hotel was hacked. Although it has been written here that the hotel access to booking.com now has 2FA authentication, so that shouldn't be easy for hackers. If I was you I'd make a formal complaint to both booking.com and the hotel and include GDPR in the title and text.
 
https://www.irishtimes.com/life-sty...ing-street-as-a-holiday-rental-on-bookingcom/ (paywalled)

Consumer watchdog was able to list 10 Downing Street as a holiday rental on booking.com​


The magazine said it set up the fake listing in minutes and noted that under booking.com’s own policies, hosts are not required to provide photo ID or proof of ownership until three months after a listing goes live.

A researcher working for the magazine listed a property on the platform on June 18th under the heading “1 bedroom apartment in the heart of London”. They included the exact address and a photograph of 10 Downing Street.

The listing was set so users had to request a stay – so nobody could book automatically without being approved.

The Which? Travel team opened the booking window briefly to allow a representative to perform a test booking. While the booking window was open, 14 people got in touch to ask if they could stay in Downing Street.

Booking.com also processed a payment from a Which? researcher for a weeklong stay in Downing Street, with the magazine saying the money had still not been refunded.

The listing was not removed until August 27th and the consumer watchdog also followed up with a fake review on August 10th rating 10 Downing Street as a 10- out-of-10 property and declaring it to be an “exceptional” option for would-be visitors.

The article includes a response from booking.com which is mostly in the kind of corporatespeak which you would expect, and claims that
the property added by Which? “was not ‘live’ or visible to customers during the period referenced, and, as the property was closed, some automatic fraud controls were not triggered”.
which doesn't seem consistent with the Which? story.
 
Back
Top