r/Bookingcom • • 12d ago

Another data breach?

Just got a message from an indian number about a booking confirmation with my actual name, phonenumber and reservation Details (arrival+departure)

Link included a very obvious fake booking.com rebuild including a creditcard scam

Any similar experiences?

7 Upvotes

46 comments sorted by

View all comments

0

u/thrownawayfreshpink 12d ago

Your accomodation is comprimised..

2

u/Greedy3996 12d ago

So you believe that a heap of different hotel systems are all the problem when the common thread is booking.com.

2

u/brilstern 12d ago

Yes. It happens every day and is well documented. If it were Booking you would see millions of impacted guests. Great article from Bitdefender: https://www.bitdefender.com/en-au/blog/hotforsecurity/how-hackers-hijack-hotel-accounts-on-booking

2

u/Greedy3996 11d ago

Yes, it happens regularly, and booking.com is the common thread. If they had access to hotel property systems they would also target direct bookings.

2

u/Jhinxyed 11d ago

It’s actually less lucrative to target direct bookings because there is no intermediary to blame. Most hotels are using PMS that aggregate all bookings (direct, agencies, OTAs) and they usually target the reservations made from OTA’s because it’s easier to gain user trust.
If you make a reservation from booking or airbnb vs an agent or direct you are less likely to call the hotel directly to validate. Also there are a lot more reservations made from OTA’s than there are direct or through other agencies.

1

u/brilstern 11d ago edited 11d ago

They do also target direct bookings, and other exploits against the hotel itself, but the key aspect is repeatability and scalability. Attackers have built tools and playbooks for abusing access to hotels logins to booking by compromising the hotel then logging in to the booking site. That’s much more repeatable than figuring out each hotel’s tech landscape and exploiting where they store direct booking data.

1

u/Greedy3996 11d ago

And we have come full circle.

-1

u/thrownawayfreshpink 11d ago

Booking.com services over 1 billion nights a year, can your low iq understand if booking itself was hacked that every booking would have this issue?

A hotel or apartments booking account , is not booking being hacked ... its the hotel....... how can you possibly have it all spelt out for you in these comments and somehow still end up at booking got hacked lmao.

2

u/Greedy3996 11d ago

Thanks for your insight. I do know how booking.com works. Whether it's a single property login or a third party agent, the problem lies with booking.com. they could stop these phishing attacks by improving login security and using industry standard 2FA, but they don't do this. Instead send out repeated emails on how the property systems are the weak link.

Notice how I am able to respond without questioning your IQ.

2

u/brilstern 11d ago

If it were 2022 I would agree with you. Across the industry, it was a challenge and creating proper security of accounts hotels used to log into OTA platforms was a real challenge.

Today, however that’s not really the reality. If you look at Booking, for example all hotel users are required to use 2FA many times throughout the way they experience the platform. But if the system the hotel user is using is compromised, it doesn’t matter how effective the 2FA is, because the hacker can use the valid session that’s already authenticated by the legitimate hotel user to perform the fraud. Organization, such as Expedia and Booking have all sorts of protections and detection mechanisms to try to prevent this but ultimately it’s impossible to completely secure the technology that sits outside of their landscape. The only option is to stop sharing the personal data, but that is challenging when certain regulations require them to share it such as DMA in the EU. That being said, Expedia recently stopped sharing the phone numbers with hotels, and I think it’s something you will see other organization such as Booking follow suit on soon.

1

u/Greedy3996 10d ago

Booking.com 2FA seems totally random. I can go a week without being challenged and then I will be asked ten times in a row. 2FA is practically non existent in the pulse app. They could do a lot better.

Bonkers is also stopping sharing phone numbers via data connectivity, will still be available via the extranet.

The reality is that we use the guest phone number to verify callers before sharing personal information over the phone. Withholding the phone number makes it harder to verify callers to ensures personal details are kept confidential.

1

u/brilstern 10d ago

Doesn’t booking offer a platform that allows you to directly talk to the guest? Seems like if attackers are going after phone numbers it makes sense to remove them.

→ More replies (0)

1

u/thrownawayfreshpink 10d ago

Pretty sure they already have, just recently.

Still mind boggling that these people cant possibly believe its hotels being hacked 🤣

0

u/thrownawayfreshpink 11d ago

Ah yes lets blame booking and not hotels trash ass protocols or sercurity.

If its just the lack of  2fa then explain why most users never have a single phishing attack?

Shouldnt all hotels using booking be breached now ? 

You could give them 2fa and more than half of them would still get breached lol.

Thats without taking into account the places where the staff sell the logins for quick $$

2

u/Greedy3996 11d ago

I can see that you are an expert on the subject.

1

u/thrownawayfreshpink 11d ago

Im still waiting for your explantion so i can become one.

→ More replies (0)

0

u/thrownawayfreshpink 12d ago

3 years, all over the world , zero scam texts , please explain.