started · updated
Booking.com addresses phishing scam involving fake Milan listings
Booking.com has addressed a security incident involving a phishing attack that allowed criminals to offer fake accommodations in Milan. The attackers gained unauthorized access to the account of the Govinda Shanty House, a legitimate Bed & Breakfast located in Monopoli, Italy.
By hijacking the legitimate account, scammers were able to use real reviews, contact details, and digital identities to list a non-existent apartment in Milan at a low price of 39 euros per night. This led to numerous international travelers booking and paying for the phantom lodging, only to find no accommodation upon arrival.
The fraudulent activity resulted in approximately 80,000 euros in bookings and an additional 30,000 euros in fraudulent commission demands. Booking.com clarified that this was not a direct hack of their platform but rather a phishing attack targeting partner accounts. Similar incidents have been reported involving other profiles in Cesenatico and Tuscany.