I was scammed via booking.com

But if an AirBnB goes wrong, well, you could be waiting…that’s the trade off.

Or worse! There have been reports of bait-and-switch scams using AirBNB (though it's by no means an AirBNB only thing) where the apartment provider makes contact on the day of travel to let you know that there's been a problem with the lovely apartment you booked (flooded or fire damaged) and they can either refund you or accommodate in a "similar" apartment. If you agree, then they have it recorded in the AirBNB conversation that you're agreeing to it. Of course the replacement apartment is 20km out of town and in a fleapit. It's another variant of the advance fee fraud.
 
So I got the runaround from Booking.com
They kept sending me the same response which, although it was signed with a person's name, I assume it was AI generated. It made no reference to previous emails.

But on Monday, the money arrived back in my account with the wording "VDP - Refund Re FRAU"

I presume that AIB has charged it back to the payment company. Or maybe they have just taken the hit.

If I had paid by Revolut, I would not have got it back.
 
It's been so long since the start of this but am I right in saying you paid by credit card ? If so how is the scammer able to get this as Visa or MC company will just not pay it ?
 
I have just received the scam message on Whatsapp regarding a booking.com reservation.
I went into the booking on the app and requested that they send the confirmation email again.
They did so I ignored the whatsapp message but reported it to booking.com.
Their customer service is terrible.
They asked for information they already had and I had already sent them.
They asked me to call them. I refused.
The last time this happended, they took no responsibility and kept me on the call, going round in circles until I gave up, having paid for the call.
This time I asked if they had reported this data breach and scam to the EU under GDPR legislation. No answer.
Only booking.com and I had my personal and travel details. If the hotel has them, booking.com gave them to them. I did not and I did not leak my details.
Why hasn't the EU or Interpol or booking.com not done anything about this widespread and lucrative scam?
If only 1 in a 1000 are caught, it is still big business.
It is time for someone to take responsibility.
 
So I booked the Leonardo Hotel in Cork via Booking.com (which was cheaper than booking directly.)

The Leonardo sent me a message containing the following:

We are aware that fraudulent messages are being sent are claiming to be from a hotel or third-party booking site asking for payment to be made or verified, this in the vast majority of cases, is fraud.

At no point will our hotels or booking sites ever send you an email, phone, WhatsApp or other platforms message requesting that payment be made via a link.

If you receive such a message, please do not click on the link and disregard the message and notify the hotel and/or the third-party booking site directly through their own messaging service as quickly as possible


This is the first time I have seen any message alerting me to the scam.
 
I told my story about being scammed on BBC Radio 4 yesterday.

Here is the link although users in Ireland can't access it. https://www.bbc.co.uk/programmes/m002krlf

They had a security expert who had researched a lot of these cases on behalf of the hotels involved.
He said that it was a phishing attack on the hotel.
Someone in the hotel clicked on a link in an email which allowed the scammers to download malware on the hotel's computer which gave them the hotel's log on details for booking.com
 
Last edited:
When searching for this thread, I came across this from two years ago where I warned about this specific scam!

 
Someone in the hotel clicked on a link in an email which allowed the scammers to download malware on the hotel's computer which gave them the hotel's log on details for booking.com
As far as I can see that still doesn't explain how the scammers were able to get access to the hotel's 2FA device/code in order to log into their Booking.com account or carry out certain actions. 2FA is mandatory on their accounts according to this so the hotel's username and password, garnered via a phishing attack, should not be enough to login and masquerade as the genuine hotel on the Booking.com platform.


Setting up two-factor authentication (2FA)​

During the registration process on our platform, it’s mandatory that you set up 2FA to give your account an extra layer of protection. With 2FA activated, you'll sign in using your username and password. In addition, we'll send a PIN to your authenticated device.

You’ll be asked to perform 2FA when you sign in to ensure your trusted device is up-to-date and correct. To further protect you and your guests from malicious or fraudulent activity, you may be prompted to repeat 2FA multiple times within 24 hours.
 
As far as I can see that still doesn't explain how the scammers were able to get access to the hotel's 2FA device/code in order to log into their Booking.com account or carry out certain actions.
Unless they got access to change the MFA device - that or MFA fatigue.
 
Back
Top