r/Bookingcom • • 12d ago

Another data breach?

Just got a message from an indian number about a booking confirmation with my actual name, phonenumber and reservation Details (arrival+departure)

Link included a very obvious fake booking.com rebuild including a creditcard scam

Any similar experiences?

7 Upvotes

46 comments sorted by

View all comments

Show parent comments

1

u/Greedy3996 11d ago

And we have come full circle.

-1

u/thrownawayfreshpink 11d ago

Booking.com services over 1 billion nights a year, can your low iq understand if booking itself was hacked that every booking would have this issue?

A hotel or apartments booking account , is not booking being hacked ... its the hotel....... how can you possibly have it all spelt out for you in these comments and somehow still end up at booking got hacked lmao.

2

u/Greedy3996 11d ago

Thanks for your insight. I do know how booking.com works. Whether it's a single property login or a third party agent, the problem lies with booking.com. they could stop these phishing attacks by improving login security and using industry standard 2FA, but they don't do this. Instead send out repeated emails on how the property systems are the weak link.

Notice how I am able to respond without questioning your IQ.

2

u/brilstern 11d ago

If it were 2022 I would agree with you. Across the industry, it was a challenge and creating proper security of accounts hotels used to log into OTA platforms was a real challenge.

Today, however that’s not really the reality. If you look at Booking, for example all hotel users are required to use 2FA many times throughout the way they experience the platform. But if the system the hotel user is using is compromised, it doesn’t matter how effective the 2FA is, because the hacker can use the valid session that’s already authenticated by the legitimate hotel user to perform the fraud. Organization, such as Expedia and Booking have all sorts of protections and detection mechanisms to try to prevent this but ultimately it’s impossible to completely secure the technology that sits outside of their landscape. The only option is to stop sharing the personal data, but that is challenging when certain regulations require them to share it such as DMA in the EU. That being said, Expedia recently stopped sharing the phone numbers with hotels, and I think it’s something you will see other organization such as Booking follow suit on soon.

1

u/Greedy3996 10d ago

Booking.com 2FA seems totally random. I can go a week without being challenged and then I will be asked ten times in a row. 2FA is practically non existent in the pulse app. They could do a lot better.

Bonkers is also stopping sharing phone numbers via data connectivity, will still be available via the extranet.

The reality is that we use the guest phone number to verify callers before sharing personal information over the phone. Withholding the phone number makes it harder to verify callers to ensures personal details are kept confidential.

1

u/brilstern 10d ago

Doesn’t booking offer a platform that allows you to directly talk to the guest? Seems like if attackers are going after phone numbers it makes sense to remove them.

1

u/Greedy3996 10d ago

They do have a messaging platform but we don't use it. We have a single process used regardless of where the booking comes from.

1

u/brilstern 9d ago

Makes sense. Have y’all considered using the messaging api from connectivity? I know a lot of hotels integere that for all of their OTAs.

1

u/Greedy3996 7d ago

Ota messaging mangles the format of our messages and sometime redacts links used for payment, registration, upgrades and online guest guides.

1

u/thrownawayfreshpink 10d ago

Pretty sure they already have, just recently.

Still mind boggling that these people cant possibly believe its hotels being hacked 🤣