Cyber experts are warning Booking.com customers about a new hacking trend dubbed “reservation hijacking” following a data breach which saw threat actors stealing customer data.
According to an email to affected customers, names, email addresses, phone numbers and booking details were accessed by threat actors, but Booking.com has yet to disclose the scale of the breach.
“We recently noticed suspicious activity affected a number of reservations and we immediately took action to contain the issue,” the email said.
While financial data has not been compromised in the breach, the stolen data could have a detrimental impact on customers and put them at risk of scams.
Norton, the cybersecurity outfit, warned that Booking.com customers could be at risk of “reservation hijacks”, where scammers pretend to be accommodation hosts to trick victims into sending money for their reservations.
“Reservation hijack scams have been around for some time, but this new data makes them much more dangerous because it gives criminals precision as they can reference the real property, the real travel dates, the right contact details to make the scam feel like routine customer service,” Luis Corrons, security evangelist at Norton, told the BBC and detailed the scams in his blog.
Recommended reading
- Microsoft Issues Warning For Booking.com Phishing Campaign
- Booking.com Confirms Customer Data Accessed in Data Breach
- Human Error Costing UK Business Billions in Data Breach Losses
The trend is not new, but the recent data breach makes the issue all the more pertinent.
“Booking.com will never ask guests to share credit card details by email, over the phone, Whatsapp or text, or ask guests to make a bank transfer that is different from the payment policy details in their booking confirmation,” the firm told the BBC, alerting customers to stay vigilant.
Reservation hijacking is all the more effective when powered by data breaches allowing threat actors to leverage real information to scam people into providing card details. Hackers pose as real hotels that customers have made genuine bookings at to ask for card information and even made up payments.





