< Back to all clusters
[TECHNOLOGY] · 3 sources

Booking.com phishing scams exploit real reservation data

Criminal groups have compromised hotel accounts in Booking.com’s extranet system, gaining access to guests’ names, travel dates and contact details. Using this information, they send WhatsApp or e‑mail messages that appear to come from the booked hotel and request a “payment correction” via a fraudulent link. The scheme, observed to rise in April 2026, leads victims to counterfeit payment sites that harvest credit‑card data.

Booking.com’s head of IT security, Predrag Vuckovic, confirmed the breach, noting that two‑factor authentication offers limited protection when the extranet credentials are stolen. The platform issues warnings to affected guests, but attacks continue. Experts advise travelers never to click links in such messages, to verify bookings through the official app or website, and to contact the hotel directly using a known phone number. Any suspicious communication should be reported to Booking.com and compromised cards should be blocked immediately.

Entities: Booking.com · Predrag Vuckovic