# European hotel reservation data breaches and fraud wave

> Live situation record from CLSTR: https://clstr.news/situations/croatia-hotel-reservation-data-breach
> Updated: 2026-09-06T09:09:35.000Z. Sources: 63. Developments: 16.

The wave of fraud targeting European hotel reservation data continues to evolve, increasingly aided by artificial intelligence. Cybersecurity experts note that AI is acting as an “accelerator,” enabling criminals to generate industrial-scale phishing attacks in seconds.

In Germany, travel organizers reported preventing an average of 74 fraud cases per month during June and July, representing a potential monthly loss of approximately €113,000. Meanwhile, the Fraudehelpdesk reported a massive surge in phishing attacks targeting online booking platforms in the first half of the year. Reports related to booking sites reached 1,072, a nearly tenfold increase compared to the same period last year. Booking.com is the primary target, accounting for over 90 percent of these reports. In 95 percent of these specific cases, fraudsters used WhatsApp as the primary communication channel, often posing as hotels to request payments via malicious links. Total phishing reports to the Fraudehelpdesk rose from 2,776 to 15,106 during the first six months, with financial damages increasing from €113,574 to €491,793. Criminals are reportedly using personal data from large-scale breaches to make messages more convincing.

Beyond phishing, the industry is seeing a rise in loyalty fraud and the ‘ClickFix’ technique. Specific account hijacking incidents continue to cause damage. In Italy, scammers hijacked the account of the Govinda Shanty House to list a non-existent ‘ghost apartment’ in Milan. This scheme resulted in approximately €80,000 in fraudulent bookings and €30,000 in fraudulent commission demands. Booking.com maintains that these incidents stem from phishing attacks targeting partner accounts rather than direct platform breaches.

## Claims

- The fraud has been reported in Germany and Romania. (corroborated by 4 sources)
- Booking.com has acknowledged the security breach and is taking remedial action. (corroborated by 3 sources)
- Phishing reports related to online booking platforms increased to 1,072 in the first half of the year. (corroborated by 3 sources)
- Over 90 percent of phishing reports regarding booking sites involve Booking.com. (corroborated by 3 sources)
- Hackers compromised hotel partner accounts on Booking.com to obtain guest data. (corroborated by 2 sources)
- The stolen data includes names, travel dates, and phone numbers of guests. (corroborated by 2 sources)
- Criminals contact travelers via Booking.com chat, WhatsApp, or SMS, pretending to be hotel staff. (corroborated by 2 sources)
- Victims are asked to verify credit‑card details or make urgent payments, resulting in theft of funds. (corroborated by 2 sources)
- Phishing messages are sent shortly before the travel date, increasing credibility. (corroborated by 2 sources)
- Total phishing reports received by Fraudehelpdesk rose from 2,776 to 15,106 in the first half of the year compared to the previous year. (corroborated by 2 sources)
- Financial losses from phishing rose from 113,574 to 491,793 euros. (corroborated by 2 sources)
- Approximately 95 percent of booking-related phishing incidents occur via WhatsApp. (single source)

## Timeline

### 2026-09-06: Booking.com phishing reports surge tenfold in first half of year

Phishing reports targeting online booking sites, primarily Booking.com, have increased nearly tenfold, with many scams conducted via WhatsApp using stolen personal data.

7 sources. https://clstr.news/cluster/bookingcom-phishing-reports-surge-tenfold-in-first-half-of-year

### 2026-08-20: Booking.com addresses phishing scam involving fake Milan listings

Scammers used a phishing attack to hijack a Booking.com partner account, listing fake Milan apartments and generating 80,000 euros in fraudulent bookings.

10 sources. https://clstr.news/cluster/bookingcom-partners-targeted-by-hackers-in-travel-fraud-schemes

### 2026-08-12: Cyberattacks target tourism industry through loyalty fraud and phishing

Cybercriminals are targeting the tourism sector using AI-driven phishing, loyalty fraud, and malware campaigns via Booking.com to steal travel rewards and install malicious software on hotel systems.

2 sources. https://clstr.news/cluster/cyberattacks-target-tourism-industry-through-loyalty-fraud-and-phishing

### 2026-08-10: Cybercriminals target hotels with fake Windows Blue Screens

A new ‘ClickFix’ phishing campaign targets European hotels using fake Booking.com emails and fraudulent Windows Blue Screens to trick employees into installing malware.

2 sources. https://clstr.news/cluster/cybercriminals-target-hotels-with-fake-windows-blue-screens

### 2026-08-08: Booking.com fraud cases and financial losses surge

Phishing and fraudulent listings on Booking.com have surged in the first half of 2026, with reported cases and economic losses significantly exceeding 2025 levels.

2 sources. https://clstr.news/cluster/bookingcom-fraud-cases-and-financial-losses-surge

### 2026-07-25: Booking.com phishing scam exploits real reservation data to steal travelers' money

Hackers compromised Booking.com hotel accounts, stole real guest data and phished travelers via chat or messenger, prompting urgent payment requests that lead to stolen funds; the scam is reported in Germany, R

6 sources. https://clstr.news/cluster/bookingcom-phishing-scams-exploit-real-reservation-data

### 2026-07-23: Booking.com data breach fuels targeted hotel reservation phishing scams

A Booking.com breach via hotel partners' systems leaked reservation details, enabling sophisticated phishing emails that have already cost victims thousands, prompting security warnings and fraud‑avoidance tips

3 sources. https://clstr.news/cluster/bookingcom-data-breach-fuels-targeted-hotel-reservation-phishing-scams

### 2026-07-23: WhatsApp Scam Impersonating Booking.com Targets Vacationers in Germany

A WhatsApp phishing scheme pretends to be Booking.com, sending German travelers a fake link that harvests personal and credit‑card data.

6 sources. https://clstr.news/cluster/whatsapp-scam-targets-holiday-travelers-with-fake-bookingcom-message

### 2026-07-19: Booking.com expands Genius loyalty program amid phishing scams

Booking.com’s Genius loyalty program offers tiered discounts and perks, while a new phishing scam pretends to give a €435 cashback, luring users to fake login sites.

2 sources. https://clstr.news/cluster/bookingcom-expands-genius-loyalty-program-amid-phishing-scams

### 2026-07-07: Booking.com data breach fuels travel‑fraud scams during peak season

Booking.com’s April data breach exposed traveler details; criminals are using the information for precise fraud scams during peak travel season, prompting the company to reset PINs and advise security steps.

2 sources. https://clstr.news/cluster/bookingcom-data-breach-fuels-travelfraud-scams-during-peak-season

### 2026-07-06: Polish hotels targeted by cyber‑fraud scheme exploiting reservation data

A breach of a hotel reservation system in Poland enabled scammers to send fake payment requests, prompting warnings to verify bookings and avoid clicking links.

5 sources. https://clstr.news/cluster/polish-hotels-targeted-by-cyberfraud-scheme-exploiting-reservation-data

### 2026-06-23: Booking.com users targeted by fraudulent payment alerts

Scammers impersonating Booking.com hotels send urgent fake payment alerts, prompting travelers to reveal card details; verify bookings directly and contact banks if compromised.

5 sources. https://clstr.news/cluster/travelers-and-homeowners-alerted-to-bookingcom-scams-and-burglary-risks

### 2026-06-21: Booking.com data breach sparks travel scams via WhatsApp

Booking.com disclosed a data breach that exposed customer details; scammers are using the leaked information on WhatsApp to run fake cancellation scams, prompting warnings from the company and authorities.

2 sources. https://clstr.news/cluster/bookingcom-data-breach-sparks-travel-scams-via-whatsapp

### 2026-06-08: Hotel and Booking Platform Data Hack Triggers Global Fraud Alerts

Hackers breached hotel and booking platforms, stealing guest data and using it in WhatsApp fraud scams; consumer groups warn against clicking payment links and urge direct verification.

2 sources. https://clstr.news/cluster/hotel-and-booking-platform-data-hack-triggers-global-fraud-alerts

### 2026-06-06: Croatian hotel reservation hack exposes data of 100,000 guests

A hack on a Croatian hotel reservation app stole data of over 100,000 guests, led to extortion attempts via WhatsApp, and is linked to a Serbian hacking group; AZOP is investigating.

2 sources. https://clstr.news/cluster/croatian-hotel-reservation-hack-exposes-data-of-100000-guests

### 2026-06-05: Croatian hotel reservation platform Phobs data breach affects ~100,000 tourists

Phobs breach exposes personal data of ~100,000 Croatian hotel guests; scammers send fake WhatsApp messages to steal payment info. Hotels and data authority warn travelers.

7 sources. https://clstr.news/cluster/croatian-hotel-booking-platform-phobs-breach-prompts-europe-wide-reservation-phishing

---
Cite as: European hotel reservation data breaches and fraud wave. CLSTR, https://clstr.news/situations/croatia-hotel-reservation-data-breach
