I was scammed via booking.com

They should also alert people for scams to watch out for just as the banks do occasionally - either via email or a prominent notice on their site.

I was not aware of the scam I fell for. Had they emailed me, I would probably have remembered it.
 
A company who respect their customers would immediately investigate where the breach was likely from (most likely the hotel), make contact with them and have all passwords and authentication changed and a email sent out to all those on the booking system to warn them about possible phishing scam.
It's al;l part of the platform model! But remember, it is the hotels who are Booking.com customers, not you! You're a product they sell to the accommodation providers.
 
It's al;l part of the platform model! But remember, it is the hotels who are Booking.com customers, not you! You're a product they sell to the accommodation providers.
yep. booking is simply a sales platform that the hotels use - but still doesn't absolve them from protecting the consumer as booking take up to 30% commission from the booking.

Booking have created a very strong brand name and the scammers prey on that name. The problem is booking is now so big that they care little about a few thousand people who may be scammed via poor security in the hotel's system that allow the scammer access details of reservations made on the booking platform.
 
but still doesn't absolve them from protecting the consumer as booking take up to 30% commission from the booking.
The're no suggestion they were compromised at any point. Every scam so far that I've seen detailed is down to an accommodation provider effectively handing over accounts and MFA keys to an attacker or an insider at the accommodation provider cooperating with an attacker.

There's not a lot more then can do, they have issued warnings on phishing and other common scams. They don't have access to the hotels systems to allow them investigate claims. They could ban hotels that allow their customers to be scammed, but then that would only hurt their business.
 
Every scam so far that I've seen detailed is down to an accommodation provider effectively handing over accounts and MFA keys to an attacker or an insider at the accommodation provider cooperating with an attacker.
Most or probably all Booking.com scam reports that I've read contained insufficient details to apportion blame with any confidence. Same for other banking etc. stories.
 
Most or probably all Booking.com scam reports that I've read contained insufficient details to apportion blame with any confidence. Same for other banking etc. stories.
I've read plenty that have, including a few cybersecurity https://blog.sekoia.io/phishing-campaigns-i-paid-twice-targeting-booking-com-hotels-and-customers/ (sources), they consistently point the finger at the accommodation providers. Look at it this way, if they did manage to compromise Booking.com itself, why would they then need to go to the bother of contacting users directly trying to con them into providing details that they could have just pulled from Booking.com?

It's also difficult to see how they could persist inside Booking.com's systems for so long that they are still able to pick off recent bookings. The reports would suggest these attacks are succeeding, if the attackers had access to Booking.com's systems, they'd be hitting far more people. They tend to hit hard and fast once they gain a foothold, not drip feeding for months or years.
 
I got this Scam Alert email from AIB today which is a good idea. Booking.com should send these occasionally. They send enough emails already on things to do in Clonakilty.

1772011787252.webp
 
A friend of mine got this email today. So Booking.com are being proactive about it. I think that they could have explained the scam a bit better.




Hello,

At Booking.com, we are dedicated to the security and data protection of our guests. In that spirit, we’re writing to inform you that unauthorized third parties may have been able to access certain booking information associated with your reservation.

We recently noticed suspicious activity affecting a number of reservations and we immediately took action to contain the issue. Based on the findings of our investigation to date, accessed information could include booking details and name(s), emails, addresses, phone numbers associated with the booking and anything that you may have shared with the accommodation.

To keep your booking secure, we have updated the PIN number of your booking reservation.

Reservation number - redacted

New PIN - redacted

If you have received suspicious emails or phone calls, these could be from malicious actors pretending to represent the accommodation or Booking.com. Please remember that:



We'll never ask you to share credit card details by email, over the phone, through text or Whatsapp



We'll never ask you to make a bank transfer that is different from the payment policy details in your booking confirmation



If you receive an email that appears to be sent by the accommodation provider or Booking.com, please remain vigilant before clicking on any links

We recommend that you have security protocols (such as an antivirus programme) set up on your devices to keep you safe from phishing attempts.

The security of your personal information is our utmost priority. We will continue to enhance and extend the robust security measures we have in place to secure your reservations with us.

We’re here to support you, so if you have any questions or concerns or notice any unexpected changes to your reservation, please do not hesitate to contact our Customer Service team, available 24/7. You can find the contact information in your reservation confirmation.

Thank you for choosing Booking.com.

Kind regards,

Booking.com
 
I got that email yesterday.
Coincidentally I received scam calls from Cyprus and Malta a few days ago.
 
I got that warning email, but the booking referred to was months ago. Not a currently active one.
 
I am not sure it's on their side.
If a scammer gets the log on details for the hotel and has access to the reservations, surely the hotel is primarily at fault?

But booking.com should have the systems in place to detect a flurry of emails from the hotel and take immediate steps to resolve it.

Which they now appear to be doing.
 
We've a few active bookings, all in Spain, coming up between my wife and I, we have 2 accounts. We got this e-mail, relating to 3 of the upcoming bookings (in seperate e-mails) but not for all of the upcoming bookings.
 
I have 2 active bookings with them and got the email yesterday identifying one of those bookings. I checked my Booking.com account this morning and the new booking reference number and PIN were already assigned to the identified booking.
 
Back
Top