Audio By Carbonatix
A data breach at travel giant Booking.com is leading to a fresh wave of scams recently dubbed "reservation hijacks".
Hackers stole customer data that experts say could lead to a surge in the scams as customers are tricked into sending criminals money.
Some customers have contacted the BBC to say they have already started receiving suspicious messages.
Booking.com says it has updated Pins for reservations and is sending out emails to affected customers warning them of the heightened risk.
But the Dutch company is refusing to say how many people have been affected and in which regions.
The platform says it has seen almost seven billion check-ins since 2010, making it one of the largest travel services in the world.
In emails to customers seen by the BBC, the company said: "We recently noticed suspicious activity affected a number of reservations and we immediately took action to contain the issue."
It goes on to say that criminals were able to access names, email addresses, phone numbers and details about past and present bookings.
It said customers' financial information was not accessed from its systems.
Experts warn this kind of data will be extremely valuable to fraudsters who are now racing to trick unwitting customers.
Cyber-security firm Norton has dubbed the scams "reservation hijacks" because criminals have contacted Booking.com customers pretending to be hotels in order to trick victims into sending them money based on bogus reservation problems.
"Reservation hijack scams have been around for some time, but this new data makes them much more dangerous because it gives criminals precision as they can reference the real property, the real travel dates, the right contact details to make the scam feel like routine customer service," said Luis Corrons, security evangelist at Norton.
Booking.com told the BBC guests should remain vigilant to potential phishing attacks.
"Booking.com will never ask guests to share credit card details by email, over the phone, Whatsapp or text, or ask guests to make a bank transfer that is different from the payment policy details in their booking confirmation," it added.
A common target
Perhaps because of its size, scammers have long abused the Booking.com platform to target customers.
Previous waves of reservation hijacks have seen hotels hacked in order to get access to the hotel's Booking.com account and send out phishing emails and text messages.
The BBC has reported on these types of scams multiple times since March 2023.
Dozens of people have contacted the BBC in recent years to say they have lost money, with one customer saying she had been "failed" by the travel firm.
Booking.com previously said it was implementing new safety features but there was "no silver bullet".
The latest hack means that fraudsters don't need to breach hotel's Booking.com administration portals - they can reach out directly to customers with convincing details to carry out their attacks.
Darren Guccione, chief executive of Keeper Security says the ongoing incident highlights the growing threat to the hospitality industry.
"When a breach at a platform the scale of Booking.com moves from data exfiltration to active phishing campaigns within days, it signals something more deliberate than opportunistic," he said.
Latest Stories
-
Middle East tension slashes IMF global growth to 3.1% for 2026
3 minutes -
TMA reopens daycare centre after microlight-aircraft crash
8 minutes -
We’re financing gov’t policy – COMAC CEO warns of mounting industry debt
9 minutes -
Kofi Arko Nokoe represents Ghana at the 2026 IMF Young Parliamentarians Initiative
12 minutes -
Fuel ‘relief’ not from gov’t – COMAC CEO says fuel cuts are industry burden
29 minutes -
Back to books – Sweden’s schools give up digital learning
54 minutes -
From One Day to One Ring: Leo Woodall joins new The Lord of the Rings cast
1 hour -
India to decide women’s quota bill as row over parliamentary seats intensifies
1 hour -
Australia’s richest person must share part of her mining fortunes, court rules
1 hour -
BBC to cut almost one in 10 staff to make £500m savings
2 hours -
Google to punish sites that trap people in with back button tricks
2 hours -
Booking.com customers warned of ‘reservation hijacking’ after hack
2 hours -
Mahama’s words can slow Parliament – Bishop Gyamfi worried over LGBTQ bill delay
2 hours -
LGBTQ Bill: We don’t want a repeat – Catholic Bishop warns Mahama could follow Akufo-Addo’s path
2 hours -
Congo to receive first group of deportees from US this week, sources say
3 hours