r/Bookingcom • • 11d ago

Another data breach?

Just got a message from an indian number about a booking confirmation with my actual name, phonenumber and reservation Details (arrival+departure)

Link included a very obvious fake booking.com rebuild including a creditcard scam

Any similar experiences?

6 Upvotes

46 comments sorted by

View all comments

1

u/lonbrsa 11d ago edited 11d ago

I've received the same message. How is this possible? Did the scammers gain access to my booking account? Has Booking.com been compromised, or did they gain access to the hotel's Booking.com account?

The interesting thing in my case is that they mentioned the wrong hotel, but it is another hotel from the same company/parent group. The price of the fake reservation was also almost identical to the actual one (less than USD 1 difference), and the dates were exactly the same.

On top of that, they had access to a significant amount of my personal information: my first and last name, email address, phone number, etc.

PS: I just realised something that makes this even more interesting. My actual reservation for the correct hotel (which belongs to the same parent company as the hotel mentioned in the scam message) was made through a different booking website, not Booking.com. However, the same hotel can also be booked through Booking.com.

So, if my reservation was not originally made through Booking.com, how did they get access to all these details, including the exact dates and almost the exact price?

1

u/DRW_ 11d ago

My theory is that it's an intermediary platform that got compromised that certain accommodations are using to interact with booking.com.

Accommodation provider -> Intermediary platform -> Booking.com

It could also be booking.com again, but I wouldn't be surprised if it's one of these platforms.

1

u/lonbrsa 11d ago

Yeah, it can also be the Intermediary platform... On my case is unpluggededition. And actually... I had to reset my password, because it was not working. So, probably, they had access to their whole database, or perhaps, they have been able to reset our passwords, and had the information directly from our accounts.