Booking.com data breach raises fresh fears over “reservation hijacking” scams

Date:

Booking.com has confirmed that hackers accessed customer reservation data, prompting renewed concern over a wave of increasingly sophisticated travel fraud known as “reservation hijacking”.

The company has warned affected users to remain alert for phishing attempts after unauthorised parties gained access to names, email addresses, phone numbers and booking details linked to some reservations. Booking.com says financial information was not accessed, but it has declined to say how many customers were affected or in which regions.

The breach, first reported in recent days, appears to have exposed precisely the kind of information that cybercriminals can use to make fraudulent messages appear credible. According to reporting by the Guardian and TechCrunch, Booking.com informed customers that third parties may have accessed “certain booking information” associated with their reservations, including anything shared with the accommodation provider. The company says it has contained the incident, updated reservation PIN numbers and contacted affected guests directly.

Cybersecurity analysts say the practical danger now lies less in the theft itself than in what follows. With access to real reservation details, fraudsters can contact travellers while posing as hotel staff or Booking.com representatives, claiming there is a payment problem, a verification issue or a risk that the reservation will be cancelled. The use of accurate travel dates, hotel names and personal contact details can make such messages far more convincing than a standard phishing email. Reports from affected users indicate that suspicious contact has already begun, including WhatsApp messages containing genuine booking information.

This pattern has become familiar to those tracking fraud in the online travel sector. Booking.com has faced repeated criticism over scams conducted through compromised hotel or partner accounts, where criminals send messages that appear to come from legitimate accommodation providers. In earlier cases, attackers gained access to hotel systems or Booking.com messaging tools and then sent false payment requests to guests. The latest breach changes the dynamic: criminals may no longer need to break into hotel portals if they can approach customers directly using stolen reservation data.

Booking.com says customers should treat any unexpected request for payment details with caution. The company has stated that it never asks guests to provide credit card information by email, phone, WhatsApp or SMS, and does not ask for a bank transfer that differs from the payment terms shown in the booking confirmation. Consumer reporting in Australia has also highlighted the scale of phishing losses more broadly, with national anti-scam figures showing that phishing scams continued to cause significant financial harm in 2025.

The company’s refusal to disclose the number of people affected is likely to intensify scrutiny. Booking.com is one of the world’s largest online travel platforms. According to the company’s own figures cited by TechCrunch, 6.8 billion customers have booked hotel rooms and homes through the service since 2010. The platform lists more than 30 million accommodation venues globally, making it an attractive target for organised cybercriminals.

The latest incident also revives questions about whether the travel industry has kept pace with the growing sophistication of digital fraud. Booking.com has been linked to previous cyber incidents, including a 2018 breach in which criminals used phishing to steal hotel employee login credentials, exposing booking data from more than 4,000 users. Dutch regulators later fined the company €475,000 for reporting that breach late. More recently, consumer complaints and media reports in several countries have pointed to continuing problems involving fake listings, impersonation scams and weak points in communication between platforms, hotels and guests.

For travellers, the immediate implication is straightforward: any message requesting urgent payment, card verification or a transfer outside the original booking terms should be treated as suspicious, even if it contains accurate reservation details. The breach suggests that stolen personal data can now be used not merely for identity theft or spam, but for targeted, time-sensitive fraud designed to strike when customers are preparing to travel. Booking.com says the issue has been contained, but the incident is likely to sharpen pressure on the company to show that its security measures are keeping pace with the scale of the threat.

EU Global Editorial Staff
EU Global Editorial Staff

The editorial team at EU Global works collaboratively to deliver accurate and insightful coverage across a broad spectrum of topics, reflecting diverse perspectives on European and global affairs. Drawing on expertise from various contributors, the team ensures a balanced approach to reporting, fostering an open platform for informed dialogue.While the content published may express a wide range of viewpoints from outside sources, the editorial staff is committed to maintaining high standards of objectivity and journalistic integrity.

Share post:

Popular

More like this
Related