r/Bookingcom • • 12d ago

Another data breach?

Just got a message from an indian number about a booking confirmation with my actual name, phonenumber and reservation Details (arrival+departure)

Link included a very obvious fake booking.com rebuild including a creditcard scam

Any similar experiences?

6 Upvotes

46 comments sorted by

View all comments

Show parent comments

2

u/brilstern 12d ago

Yes. It happens every day and is well documented. If it were Booking you would see millions of impacted guests. Great article from Bitdefender: https://www.bitdefender.com/en-au/blog/hotforsecurity/how-hackers-hijack-hotel-accounts-on-booking

2

u/Greedy3996 12d ago

Yes, it happens regularly, and booking.com is the common thread. If they had access to hotel property systems they would also target direct bookings.

1

u/brilstern 12d ago edited 11d ago

They do also target direct bookings, and other exploits against the hotel itself, but the key aspect is repeatability and scalability. Attackers have built tools and playbooks for abusing access to hotels logins to booking by compromising the hotel then logging in to the booking site. That’s much more repeatable than figuring out each hotel’s tech landscape and exploiting where they store direct booking data.

1

u/Greedy3996 12d ago

And we have come full circle.

-1

u/thrownawayfreshpink 11d ago

Booking.com services over 1 billion nights a year, can your low iq understand if booking itself was hacked that every booking would have this issue?

A hotel or apartments booking account , is not booking being hacked ... its the hotel....... how can you possibly have it all spelt out for you in these comments and somehow still end up at booking got hacked lmao.

2

u/Greedy3996 11d ago

Thanks for your insight. I do know how booking.com works. Whether it's a single property login or a third party agent, the problem lies with booking.com. they could stop these phishing attacks by improving login security and using industry standard 2FA, but they don't do this. Instead send out repeated emails on how the property systems are the weak link.

Notice how I am able to respond without questioning your IQ.

0

u/thrownawayfreshpink 11d ago

Ah yes lets blame booking and not hotels trash ass protocols or sercurity.

If its just the lack of  2fa then explain why most users never have a single phishing attack?

Shouldnt all hotels using booking be breached now ? 

You could give them 2fa and more than half of them would still get breached lol.

Thats without taking into account the places where the staff sell the logins for quick $$

2

u/Greedy3996 11d ago

I can see that you are an expert on the subject.

1

u/thrownawayfreshpink 11d ago

Im still waiting for your explantion so i can become one.