< Back to situation

[REVISION HISTORY]

European hotel reservation data breaches and fraud wave

Updated 7 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-21 05:26 UTC → 2026-09-06 10:23 UTC · added removed

The wave of fraud targeting European hotel reservation data continues to evolve, increasingly aided by artificial intelligence. Cybersecurity experts note that AI is acting as an “accelerator,” enabling criminals to generate industrial-scale phishing attacks in seconds. In Germany, travel organizers reported preventing an average of 74 fraud cases per month during June and July, representing a potential monthly loss of approximately €113,000. Meanwhile, the Fraudehelpdesk reported a massive surge in phishing attacks targeting online booking platforms in the first half of the year. Reports related to booking sites reached 1,072, a nearly tenfold increase compared to the same period last year. Booking.com is the primary target, accounting for over 90 percent of these reports. In 95 percent of these specific cases, fraudsters used WhatsApp as the primary communication channel, often posing as hotels to request payments via malicious links. Total phishing reports to the Fraudehelpdesk rose from 2,776 to 15,106 during the first six months, with financial damages increasing from €113,574 to €491,793. Criminals are reportedly using personal data from large-scale breaches to make messages more convincing. Beyond phishing, the industry is seeing a rise in loyalty fraud, where attackers steal bonus points or flight miles for free travel. The ‘ClickFix’ technique remains a significant threat to hotel operators. In this method, attackers impersonate guests or official platform messages to trick employees into executing malicious PowerShell commands via fraud and the Windows ‘Run’ dialog, bypassing traditional security measures to install malware. ‘ClickFix’ technique. Specific incidents of account hijacking incidents continue to cause significant financial damage. In Italy, scammers gained unauthorized access to hijacked the account of the Govinda Shanty House, a legitimate Bed & Breakfast, House to list a non-existent ‘ghost apartment’ in Milan. By leveraging the legitimate account’s real reviews and digital identity, attackers lured international travelers into bookings priced at €39 per night. This specific scheme resulted in approximately €80,000 in fraudulent bookings and an additional €30,000 in fraudulent commission demands. Similar profile hijacks have been reported in Cesenatico and Tuscany. Booking.com maintains that these incidents stem from phishing attacks targeting partner accounts rather than direct platform breaches.

Versions

  1. 2026-09-06 10:23 UTC European hotel reservation data breaches and fraud wave
  2. 2026-08-21 05:26 UTC European hotel reservation data breaches and fraud wave
  3. 2026-08-20 20:53 UTC European hotel reservation data breaches and fraud wave
  4. 2026-08-13 05:31 UTC European hotel reservation data breaches and fraud wave
  5. 2026-08-10 10:02 UTC European hotel reservation data breaches and fraud wave
  6. 2026-08-09 20:21 UTC European hotel reservation data breaches and fraud wave
  7. 2026-07-29 16:28 UTC Hotel reservation data breaches and scams
  8. 2026-07-27 08:45 UTC Hotel reservation data breaches and scams

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.