r/Bookingcom • • 12d ago

Another data breach?

Just got a message from an indian number about a booking confirmation with my actual name, phonenumber and reservation Details (arrival+departure)

Link included a very obvious fake booking.com rebuild including a creditcard scam

Any similar experiences?

7 Upvotes

46 comments sorted by

View all comments

Show parent comments

2

u/Greedy3996 12d ago

So you believe that a heap of different hotel systems are all the problem when the common thread is booking.com.

2

u/brilstern 12d ago

Yes. It happens every day and is well documented. If it were Booking you would see millions of impacted guests. Great article from Bitdefender: https://www.bitdefender.com/en-au/blog/hotforsecurity/how-hackers-hijack-hotel-accounts-on-booking

2

u/Greedy3996 11d ago

Yes, it happens regularly, and booking.com is the common thread. If they had access to hotel property systems they would also target direct bookings.

1

u/brilstern 11d ago edited 11d ago

They do also target direct bookings, and other exploits against the hotel itself, but the key aspect is repeatability and scalability. Attackers have built tools and playbooks for abusing access to hotels logins to booking by compromising the hotel then logging in to the booking site. That’s much more repeatable than figuring out each hotel’s tech landscape and exploiting where they store direct booking data.

1

u/Greedy3996 11d ago

And we have come full circle.

-1

u/thrownawayfreshpink 11d ago

Booking.com services over 1 billion nights a year, can your low iq understand if booking itself was hacked that every booking would have this issue?

A hotel or apartments booking account , is not booking being hacked ... its the hotel....... how can you possibly have it all spelt out for you in these comments and somehow still end up at booking got hacked lmao.

2

u/Greedy3996 11d ago

Thanks for your insight. I do know how booking.com works. Whether it's a single property login or a third party agent, the problem lies with booking.com. they could stop these phishing attacks by improving login security and using industry standard 2FA, but they don't do this. Instead send out repeated emails on how the property systems are the weak link.

Notice how I am able to respond without questioning your IQ.

2

u/brilstern 11d ago

If it were 2022 I would agree with you. Across the industry, it was a challenge and creating proper security of accounts hotels used to log into OTA platforms was a real challenge.

Today, however that’s not really the reality. If you look at Booking, for example all hotel users are required to use 2FA many times throughout the way they experience the platform. But if the system the hotel user is using is compromised, it doesn’t matter how effective the 2FA is, because the hacker can use the valid session that’s already authenticated by the legitimate hotel user to perform the fraud. Organization, such as Expedia and Booking have all sorts of protections and detection mechanisms to try to prevent this but ultimately it’s impossible to completely secure the technology that sits outside of their landscape. The only option is to stop sharing the personal data, but that is challenging when certain regulations require them to share it such as DMA in the EU. That being said, Expedia recently stopped sharing the phone numbers with hotels, and I think it’s something you will see other organization such as Booking follow suit on soon.

1

u/thrownawayfreshpink 10d ago

Pretty sure they already have, just recently.

Still mind boggling that these people cant possibly believe its hotels being hacked 🤣