IndustryNews In BriefManagementNewsManagement Rights

Booking.com breach puts guests and accommodation operators on phishing alert

The latest data breach is not just a problem for guests. For accommodation operators, it could mean more phishing attempts, more guest confusion and more pressure on frontline teams.

Booking.com has warned some customers that their personal booking information may have been accessed by unauthorised third parties, prompting fresh concern for travellers and accommodation operators alike. Public reports published on April 13 and 14 said the company had begun notifying affected customers after identifying suspicious activity linked to a number of reservations.

In an email to customers, Booking.com said it had detected suspicious activity affecting a number of reservations and had taken immediate action to contain the issue. The company said its investigation found that unauthorised third parties may have accessed booking information including names, email addresses, phone numbers, booking details and information shared with the property. Affected customers were sent updated reservation PINs and warned to remain alert to malicious actors impersonating either Booking.com or the accommodation provider.

“The security of your personal information is our utmost priority,” the email said.

“We’ll continue to enhance and extend the robust security measures we have in place to secure your reservations with us.”

Customers were also advised to be cautious of suspicious emails, phone calls and links, and to make sure security protections such as antivirus software were in place on their devices. Booking.com said financial information was not accessed from its systems, although it has not disclosed how many customers were affected.

Read: Owner “shattered” as Booking.com ignores pleas over serial reviewer

For accommodation operators, the incident is more than a platform security issue. Because the exposed data reportedly includes real reservation details and guest contact information, the breach may increase the risk of phishing emails, texts or calls that appear to come from either Booking.com or the property itself. That leaves operators vulnerable to guest confusion, reputational fallout and extra pressure on front desk and reservations teams, even where the property’s own systems were not compromised.

That operator risk is what makes the breach especially relevant to the sector. When scammers have enough detail to make a message look legitimate, guests are more likely to contact the property directly to verify payment requests, booking changes or suspicious communication. In practice, that can turn a third-party cyber incident into a property-level customer service and fraud-prevention issue.

Read: From cheeky chargebacks to cyber fraud: Scams that cost the industry $$$$$

While Booking.com says financial information was not accessed from its systems, key questions remain unanswered, including the full scale of the breach and how many customers were affected. For operators, the episode is another reminder that cyber risk is no longer confined to back-end systems. It now sits squarely in the guest experience space, where trust, communication and payment confidence can all be affected by a breach that happens elsewhere in the booking chain.

A practical takeaway for properties may be to remind staff and guests of official payment procedures, reinforce that credit card details should never be requested through informal channels, and be ready to respond quickly to suspicious communications linked to bookings.

Booking.com itself told affected customers it would never ask for card details by email, over the phone, through text or WhatsApp, and would never request a bank transfer that differs from the payment policy shown in the booking confirmation.

Read the latest edition of AccomNews HERE

Mandy Clarke

Mandy Clarke has over two decades of experience writing about the accommodation and tourism industries and is an accomplished editor. She is the long-time former editor of AccomNews and the current editor of Resort News, two leading publications serving Australia and New Zealand's accommodation sector.

She previously spent almost 20 years as co-director of Multimedia Pty Ltd, helping shape the company into a trusted B2B content provider for the accommodation and education sectors in Australia and New Zealand. During this time, she oversaw high-quality print and digital content for key publications including AccomNews, Resort News, School News, and the property listing platform AccomProperties.

Her contributions to the industry have been recognised with the Female Leader Award at the Best of Tourism 2023 and the ARAMA Life Member Award in 2024.

Leave a comment for the community...

Your email address will not be published. Required fields are marked *

Back to top button
WP Tumblr Auto Publish Powered By : XYZScripts.com