Skip to main content

These days, scams linked to Booking.com have become harder to spot because they no longer rely solely on generic, poorly written or randomly sent emails. In many cases, attackers use genuine booking details, such as the name of the accommodation, dates of stay, confirmation number and the traveller’s personal details.

This is what makes the scam so effective: the message appears to come from a legitimate source and contains information that only Booking.com, the hotel or the customer should know.

 

Where does the data used in these scams come from?

The most important point to clarify is this: in most cases, it is not a matter of a direct breach of Booking.com’s central systems, but of unauthorised access to partner accommodation accounts.

For a cybercriminal, gaining access to a hotel’s account means being able to view genuine booking details and, in some cases, contact guests via channels that appear trustworthy.

How the breach occurs

Attackers often target accommodation staff, using phishing emails designed to look like operational communications, guest complaints or urgent requests. In other cases, they exploit previously stolen credentials, malware on company devices or vulnerabilities in third-party software and plugins used by hotels.

What data is used

Even when payment details are not exposed, attackers may still obtain enough information to mount a credible scam: first and last name, email address, telephone number, the booked property, dates of stay, messages exchanged with the hotel and the actual booking reference number.

 

Why do these attacks work?

The difference compared to traditional phishing is the precision. Here, the message does not simply say ‘your account is blocked’. It states, for example, that a booking at a certain property, on a certain date, is at risk of being cancelled unless a verification is completed immediately. It is spear phishing: an attack tailored specifically to a particular individual. In detail:

  • In-app messages, emails and WhatsApp: after compromising a partner account, fraudsters can send communications that appear to come from the accommodation provider. The most common pretext is an alleged card verification, a failed payment or the need to confirm the booking to avoid cancellation
  • Fraudulent text messages and phone calls: some campaigns use text messages simulating imminent charges or payment issues. The aim is to pressure the victim into clicking a link, calling a fake number or providing bank details at a time of extreme urgency
  • cloned pages: the links often lead to websites that mimic the interface of Booking.com or the booked accommodation. The page may look professional, but it is designed to steal login credentials, card details and OTP codes.

 

Warning signs not to be ignored

The problem is that these messages can appear genuine. This is precisely why you need to focus on unusual behaviour, not just the visual appearance of the communication:

  • forced urgency: requests for immediate action within a few hours, often accompanied by the threat of cancellation of your stay
  • requests outside official channels: payments, bank transfers, card details or verification codes requested via WhatsApp, SMS, external email or unverifiable links
  • suspicious links: addresses that do not match the official domain, shortened URLs, unusual characters or pages asking you to re-enter details already provided during the booking process
  • payment inconsistencies: during the transaction, the name of the payee, the merchant or the payment page does not match the booked accommodation or Booking.com.

 

How to protect yourself before and after a scam attempt

The basic rule is simple: never trust a link received when you’re under pressure. Even if the message contains correct details, verification must always be carried out by the user, not via the link provided by the sender.

Preventative measures for travellers

To determine whether a communication is genuinely trustworthy, it is worth looking out for certain recurring signs that often indicate a scam attempt:

  • only access the Booking.com app or official website: if you receive a payment or verification request, close the message and manually open the Booking.com app or website. Check your booking there
  • Do not share sensitive details via chat: card numbers, OTP codes, login details and bank transfer details must not be disclosed via messages, even if the contact appears to be the booked accommodation
  • Protect your account: use a unique password that is not reused on other services, and enable two-factor authentication where available.

 

What should you do if you’ve already clicked on a link or entered your details?

If you’ve already opened a suspicious link or entered personal or banking details, the priority is to minimise the damage immediately and prevent further unauthorised access:

  1. Change your password straight away: update your Booking.com account credentials and those of any other services where you’ve used the same password;
  2. Contact your bank: if you have entered payment details, block or monitor your card and report the suspicious transaction to your bank immediately;
  3. Report the incident: inform Booking.com’s official support team, the accommodation provider via a verified contact, and, in the event of fraud, the Postal Police.

 

The illusion of trust

Booking scams clearly illustrate a well-established trend in cybersecurity: phishing is no longer just a problem of suspicious emails, but one of compromised trust. If a criminal manages to use genuine data and seemingly legitimate channels, the victim falls for the scam not because they are distracted, but because the context appears coherent.

This is why the actual details of a booking are no longer enough to prove the authenticity of a message. The most effective defence remains the same: interrupt the flow imposed by the attacker, do not click on the link received, and verify everything directly through official channels.