Booking.com data breach fuels targeted hotel reservation phishing scams
On April 13, Booking.com disclosed that unauthorized parties accessed personal reservation data through hotel partners’ management systems after infecting them with ClickFix malware. The stolen information includes guests’ names, email addresses, phone numbers, travel dates and hotel details. Criminals are now using these data points to craft highly convincing phishing emails that appear to come from Booking.com, prompting victims to enter payment credentials on cloned sites. A documented case in Madrid resulted in a family losing €3,800 after falling for such a message.
Booking.com emphasizes that financial details and passwords stored on its own platform were not compromised, but warns travelers to scrutinize email sender domains and to verify URLs, use HTTPS, and compare official prices before providing any personal or payment information.
Security experts recommend checking for subtle misspellings in web addresses, confirming the site’s SSL certificate, and searching for the hotel directly via a trusted browser to avoid counterfeit booking pages.