I was scammed via booking.com

I am the administrator of Clayton Hotel Dublin Airport Your Booking ID [ correct booking number]
The only way the scammers could get the correct customer name, email address, booking number is by compromising either (a) booking.com itself, (b) the hotel's admin account on booking.com or their own email system, or (c) the customer's own email or account on booking.com.

We have heard in the past the scammers do it by compromising the hotel's admin account on booking.com, which suggests poor password protection, but we have also heard that 2FA was introduced which should prevent this. The fact that multiple people at a hotel are likely to use their admin account makes this a weak point from a security POV.

If the hotel's admin account or email was compromised, is the hotel liable under GDPR for not protecting customer data (potential penalty 4% of revenues)?
 
I got a WhatsApp message and a text today from "booking.com".

The text listed my first name, the WhatsApp message listed my full name.

The text asked to click a link for "confirmation on your phone!" - using the exclamation mark, c'mon :rolleyes:

The WhatsApp was more professional looking and it listed the property and dates that I did book - only I had also cancelled it about 3 weeks ago, so easy to spot the phish, not least that the phone number is from the Domincan Republic!
1776879883625.webp
 
I have an upcoming booking with booking.com in a European city. I got a few texts messages - via WhatsApp, asking me to clarify payment methods or some such. And if I didn’t my booking would be cancelled. After the second one I went through booking.com and contacted the property and they confirmed it was a scam.
If I had actually checked the country code of where the message came from I would have determined that myself - I think it was from Indonesia. I’m usually very vigilant but you can get caught,
 
I'm still confused about who is the weak link in the chain in most of these scams. Booking.com? The accommodation provider? Both? Has it been ascertained and clarified exactly how such scams work?
 
It's not clear and I suppose that booking.com doesn't want to alert people to whatever systems weaknesses there are.

My understanding is that there are two types
1) The hotel's log in details are got by the criminals and only that hotel is impacted
2) Booking.com itself has suffered a data breach of its systems.
 
I've an apartment booked with booking.com in Ireland for October. The provider messaged me via the portal to inform me they can give me a better rate if I book directly and they've sent me their email address. Not a scam but it's interesting. Thanks to on here I'll be careful to check the email is real and phone them up as well to be certain. I'm in two minds about booking directly, I don't like to though, as it smells off.
 
And if it's genuine and you start dealing with the accommodation provider directly and off the Booking.com platform then, almost certainly, you'll lose any protection that using the platform offers in case that's relevant.
 
  • Like
Reactions: Leo
Back
Top