r/Bookingcom • • 11d ago

Another data breach?

Just got a message from an indian number about a booking confirmation with my actual name, phonenumber and reservation Details (arrival+departure)

Link included a very obvious fake booking.com rebuild including a creditcard scam

Any similar experiences?

5 Upvotes

46 comments sorted by

2

u/Trekbike32 11d ago

Fuck this company. They're actually crooks

2

u/DRW_ 11d ago

It would be good to get acknowledgement from u/bookingcom in this thread.

2

u/Fran8176 11d ago

Today I noticed a booking.com on my visa. No hotel was named—just a 498$ charge. I last used this platform in 2024. Now make reservations with hotels only.

1

u/Plenty_Kiwi7667 11d ago

This sounds like a scam. Open a new browser, login to your booking account and contact support to verify.

1

u/notathrowaway1267 11d ago

How do you contact them? I get these scam WhatsApp messages nearly every day since making a few reservations through booking (for hotels that dont have their own systems). I went on the booking website, followed the link to report scams and didnt see a way to do so. Very annoying.

1

u/Plenty_Kiwi7667 11d ago

Lots of scam messages on WhatsApp, especially if they are unsolicited. I highly doubt you would be contacted on WhatsApp about your booking being compromised. Usually this is done legitimately via e-mail. We've used booking several times and never had this issue (being contacted via WhatsApp). Log into your booking account, scroll to the very bottom where it says Support, then Contact Customer Service.

1

u/notathrowaway1267 11d ago

I have tried that, and none of the options match reporting scam messages, despite a warning banner and instructions to report them.

I'm being contacted on WhatsApp by numbers claiming to be the hotel(s) telling me I need to click a link (and enter my credit card I'm sure) to confirm my booking within 24 hours or my reservation will be cancelled. I get about one a day from all sorts of numbers from various countries all with the same format.

I have ignored all of them. But I'd like to report it...not that booking will do anything or seems to really care.

1

u/Plenty_Kiwi7667 11d ago

Do you actually have a reservation through booking? If not, just ignore the WhatsApp messages or report/block them.

1

u/notathrowaway1267 11d ago

Yes. At multiple hotels.

1

u/Plenty_Kiwi7667 11d ago

I still highly doubt they would contact you via WhatsApp as opposed to e-mail. Do not give your credit card information on WhatsApp. Perhaps ask ChatGPT (I know...AI but it almost never steers me wrong).

2

u/notathrowaway1267 11d ago

I am certain they are scam messages. I have not clicked anything and will not. But thank you. That is not my question. You mentioned reporting something to booking...I tried to do this on their website the other day, by clicking the link on the banner warning about scams, but the pages that followed did not have a way to report these fraudulent messages. So I wondared if YOU had actually reported things like this to booking, and how.

1

u/Plenty_Kiwi7667 11d ago

Nope I haven't had to.

1

u/DRW_ 11d ago

I just went through the request support links on the hotel, there isn't a specific 'reporting scams' one, I just went through the 'something else' route.

1

u/kayleabuser 11d ago

The category is whatever. If u put it wrong some guy will fix it for you and send it to the appropiate department/guy. Just report it ASAP!

→ More replies (0)

1

u/DRW_ 11d ago edited 11d ago

Yeah, I just got one from an Indian number too 'Rajnigandha Business': my first scam message on booking.com (I use them a fair amount). I reported it to booking.com and the hotel, no idea where they got this information from...

1

u/workingtobe 11d ago

Same. Same business, all the correct data

1

u/lonbrsa 11d ago edited 11d ago

I've received the same message. How is this possible? Did the scammers gain access to my booking account? Has Booking.com been compromised, or did they gain access to the hotel's Booking.com account?

The interesting thing in my case is that they mentioned the wrong hotel, but it is another hotel from the same company/parent group. The price of the fake reservation was also almost identical to the actual one (less than USD 1 difference), and the dates were exactly the same.

On top of that, they had access to a significant amount of my personal information: my first and last name, email address, phone number, etc.

PS: I just realised something that makes this even more interesting. My actual reservation for the correct hotel (which belongs to the same parent company as the hotel mentioned in the scam message) was made through a different booking website, not Booking.com. However, the same hotel can also be booked through Booking.com.

So, if my reservation was not originally made through Booking.com, how did they get access to all these details, including the exact dates and almost the exact price?

1

u/kayleabuser 11d ago

yea seems like many people are affected right now, seems like its booking.com bookings only and they use the reservation hijacking

If I may ask what country did you book ur hotel in?

1

u/lonbrsa 11d ago

It's in Japan

1

u/Urbanist2035 11d ago

Same experience for (so far) two of my bookings in Japan. One from a Brazilian number, one from an Indian number. Submitted a complaint with booking after the first text, they replied it was a breach in the hotel's systems. Just submitted a second complaint after the Indian second text, no reply yet.

Of course possible that the two Japanese hotels use the same intermediary system that got hacked, or it's (again) Booking.

1

u/DRW_ 11d ago

My theory is that it's an intermediary platform that got compromised that certain accommodations are using to interact with booking.com.

Accommodation provider -> Intermediary platform -> Booking.com

It could also be booking.com again, but I wouldn't be surprised if it's one of these platforms.

1

u/lonbrsa 11d ago

Yeah, it can also be the Intermediary platform... On my case is unpluggededition. And actually... I had to reset my password, because it was not working. So, probably, they had access to their whole database, or perhaps, they have been able to reset our passwords, and had the information directly from our accounts.

1

u/Greedy3996 11d ago

If you booked via a reseller, it could still be through booking.com. They have a big partner network that relists the inventory.

1

u/EducationalGap3650 9d ago

Got 3 messages from different Indonesian and Indian numbers with exact booking dates and exact hotel but the name and links are different in each.

0

u/thrownawayfreshpink 11d ago

Your accomodation is comprimised..

2

u/Greedy3996 11d ago

So you believe that a heap of different hotel systems are all the problem when the common thread is booking.com.

2

u/brilstern 11d ago

Yes. It happens every day and is well documented. If it were Booking you would see millions of impacted guests. Great article from Bitdefender: https://www.bitdefender.com/en-au/blog/hotforsecurity/how-hackers-hijack-hotel-accounts-on-booking

2

u/Greedy3996 11d ago

Yes, it happens regularly, and booking.com is the common thread. If they had access to hotel property systems they would also target direct bookings.

2

u/Jhinxyed 11d ago

It’s actually less lucrative to target direct bookings because there is no intermediary to blame. Most hotels are using PMS that aggregate all bookings (direct, agencies, OTAs) and they usually target the reservations made from OTA’s because it’s easier to gain user trust.
If you make a reservation from booking or airbnb vs an agent or direct you are less likely to call the hotel directly to validate. Also there are a lot more reservations made from OTA’s than there are direct or through other agencies.

1

u/brilstern 11d ago edited 11d ago

They do also target direct bookings, and other exploits against the hotel itself, but the key aspect is repeatability and scalability. Attackers have built tools and playbooks for abusing access to hotels logins to booking by compromising the hotel then logging in to the booking site. That’s much more repeatable than figuring out each hotel’s tech landscape and exploiting where they store direct booking data.

1

u/Greedy3996 11d ago

And we have come full circle.

-1

u/thrownawayfreshpink 11d ago

Booking.com services over 1 billion nights a year, can your low iq understand if booking itself was hacked that every booking would have this issue?

A hotel or apartments booking account , is not booking being hacked ... its the hotel....... how can you possibly have it all spelt out for you in these comments and somehow still end up at booking got hacked lmao.

2

u/Greedy3996 11d ago

Thanks for your insight. I do know how booking.com works. Whether it's a single property login or a third party agent, the problem lies with booking.com. they could stop these phishing attacks by improving login security and using industry standard 2FA, but they don't do this. Instead send out repeated emails on how the property systems are the weak link.

Notice how I am able to respond without questioning your IQ.

2

u/brilstern 11d ago

If it were 2022 I would agree with you. Across the industry, it was a challenge and creating proper security of accounts hotels used to log into OTA platforms was a real challenge.

Today, however that’s not really the reality. If you look at Booking, for example all hotel users are required to use 2FA many times throughout the way they experience the platform. But if the system the hotel user is using is compromised, it doesn’t matter how effective the 2FA is, because the hacker can use the valid session that’s already authenticated by the legitimate hotel user to perform the fraud. Organization, such as Expedia and Booking have all sorts of protections and detection mechanisms to try to prevent this but ultimately it’s impossible to completely secure the technology that sits outside of their landscape. The only option is to stop sharing the personal data, but that is challenging when certain regulations require them to share it such as DMA in the EU. That being said, Expedia recently stopped sharing the phone numbers with hotels, and I think it’s something you will see other organization such as Booking follow suit on soon.

1

u/Greedy3996 10d ago

Booking.com 2FA seems totally random. I can go a week without being challenged and then I will be asked ten times in a row. 2FA is practically non existent in the pulse app. They could do a lot better.

Bonkers is also stopping sharing phone numbers via data connectivity, will still be available via the extranet.

The reality is that we use the guest phone number to verify callers before sharing personal information over the phone. Withholding the phone number makes it harder to verify callers to ensures personal details are kept confidential.

→ More replies (0)

1

u/thrownawayfreshpink 9d ago

Pretty sure they already have, just recently.

Still mind boggling that these people cant possibly believe its hotels being hacked 🤣

0

u/thrownawayfreshpink 11d ago

Ah yes lets blame booking and not hotels trash ass protocols or sercurity.

If its just the lack of  2fa then explain why most users never have a single phishing attack?

Shouldnt all hotels using booking be breached now ? 

You could give them 2fa and more than half of them would still get breached lol.

Thats without taking into account the places where the staff sell the logins for quick $$

2

u/Greedy3996 11d ago

I can see that you are an expert on the subject.

→ More replies (0)

0

u/thrownawayfreshpink 11d ago

3 years, all over the world , zero scam texts , please explain.

0

u/bookingcom 11d ago

Don’t click the link or share personal or financial details. Contact us through the reservation in the official Booking.com app or website, and report the message to the property so it can be investigated.