< Back to all clusters
[CRIME] · Netherlands · 2 sources

Booking.com data breach fuels travel‑fraud scams during peak season

Booking.com confirmed that in April unauthorized parties accessed personal data of a portion of its customers, including full names, email addresses, phone numbers, mailing addresses and reservation details. Financial information was not compromised, but the breach was reported to the Dutch regulator 22 days late, exposing the company to a potential €475,000 fine.

Criminal groups are now exploiting the stolen data to carry out targeted fraud against travelers who have confirmed bookings. Scammers send highly personalized phishing messages that reference the hotel, travel dates and payment amounts, making the fraud difficult to detect. Victims risk having reservations altered or cancelled, facing extra accommodation costs, or arriving at destinations to find no room available.

Booking.com responded by resetting PIN codes for affected reservations and notifying users. Security experts advise travelers to verify bookings directly with hotels, ignore unexpected payment requests, keep original payment confirmations, and report any unrecognised charges immediately.