Your hotel message may know your booking—and still be a scam
Security researchers linked reservation-hijacking scams to more than 350 accommodations in 50 countries, showing why a message that quotes your real trip details still needs independent verification.
Real booking details make the lure
A text or email saying a hotel payment failed, or that a reservation is at risk, can feel convincing when it names the property, dates or price. In reservation hijacking, criminals use real booking context to impersonate the accommodation and push a guest toward an urgent payment link. The Associated Press reported this month that scammers can obtain those details by phishing hotel staff and accessing legitimate reservation information; cybersecurity researchers told WIRED that fake pages can be tailored with a guest’s real stay dates and hotel name. ap +1
Gen Digital’s security researchers say they identified more than 350 accommodations in 50 countries linked to the scam flows they analyzed, including fraudulent messages and payment pages. That is not a count of confirmed victims or proof that every named property’s own database was breached: the researchers say the source of exposed reservation context can vary. gendigital +1
A real booking is not proof
The risk is not hypothetical. In April, Booking.com said unauthorized parties had accessed some guests’ booking information. The company told affected customers that exposed details could include names, contact information and booking data, while saying financial information was not accessed; it did not disclose how many guests were affected. theguardian +1
Booking details can be exposed through different routes, and a convincing message does not establish which one was used. The researchers’ analysis describes a broader set of scam flows, so the Booking.com incident should not be treated as the explanation for every case. What matters to travelers is that a message can contain accurate information and still direct them to a criminal payment page. gendigital +1
Verify through a channel you choose
Do not use a link or phone number in an unexpected message asking you to confirm payment, re-enter card details or avoid cancellation. Open the travel platform’s app or website yourself, or contact the hotel using details from your original confirmation or its official website. The FTC advises travelers to type a company’s known web address directly rather than rely on a message link. ap +2
Booking.com says it will not ask guests to share card details by email, phone, text or WhatsApp, or to make a bank transfer that differs from the booking’s stated payment policy. Check that policy in your confirmation before paying. If you already entered card details on a suspicious page, contact your bank or payment provider immediately and monitor the account for unauthorized charges. booking