Particle.news
Download on the App Store

Phishing Ring Uses Compromised Booking.com Hotel Accounts to Steal Payments

Security reports say attackers use real reservation details to message guests then funnel them to fake payment pages.

Overview

  • Reports that surfaced Monday say criminals gained access to hotels' Booking.com management accounts and copied guest names, travel dates and phone numbers.
  • Using those real booking details, attackers pose as hotel staff in messenger apps and claim a payment failed to prompt victims to follow a supplied link.
  • The links lead to convincingly designed fake payment pages where victims are asked to enter card and payment data that the attackers then steal.
  • Experts advise travelers to check any payment request in the official Booking.com app or website and to call the hotel on a phone number found independently.
  • If payment data was entered, victims should immediately contact their card issuer to block the card, report the incident to the platform and notify police.