Overview
- Reports that surfaced Monday say criminals gained access to hotels' Booking.com management accounts and copied guest names, travel dates and phone numbers.
- Using those real booking details, attackers pose as hotel staff in messenger apps and claim a payment failed to prompt victims to follow a supplied link.
- The links lead to convincingly designed fake payment pages where victims are asked to enter card and payment data that the attackers then steal.
- Experts advise travelers to check any payment request in the official Booking.com app or website and to call the hotel on a phone number found independently.
- If payment data was entered, victims should immediately contact their card issuer to block the card, report the incident to the platform and notify police.