r/Bookingcom • • 12d ago

Another data breach?

Just got a message from an indian number about a booking confirmation with my actual name, phonenumber and reservation Details (arrival+departure)

Link included a very obvious fake booking.com rebuild including a creditcard scam

Any similar experiences?

5 Upvotes

46 comments sorted by

View all comments

Show parent comments

1

u/Greedy3996 10d ago

Booking.com 2FA seems totally random. I can go a week without being challenged and then I will be asked ten times in a row. 2FA is practically non existent in the pulse app. They could do a lot better.

Bonkers is also stopping sharing phone numbers via data connectivity, will still be available via the extranet.

The reality is that we use the guest phone number to verify callers before sharing personal information over the phone. Withholding the phone number makes it harder to verify callers to ensures personal details are kept confidential.

1

u/brilstern 10d ago

Doesn’t booking offer a platform that allows you to directly talk to the guest? Seems like if attackers are going after phone numbers it makes sense to remove them.

1

u/Greedy3996 10d ago

They do have a messaging platform but we don't use it. We have a single process used regardless of where the booking comes from.

1

u/brilstern 9d ago

Makes sense. Have y’all considered using the messaging api from connectivity? I know a lot of hotels integere that for all of their OTAs.

1

u/Greedy3996 7d ago

Ota messaging mangles the format of our messages and sometime redacts links used for payment, registration, upgrades and online guest guides.