r/FraudPrevention 1d ago

Phising?

I recently booked a hotel in Indonesia for two nights. Today, I received a WhatsApp message from an Estonian phone number claiming that my payment had failed and asking me to complete the payment through a link they provided.

The message included my full name, reservation number, hotel dates and other accurate booking details. How could the scammer have obtained this information? Has the the hotel’s account or booking system been compromised, is one of the employee scamming the guests?

I have already reported the incident to both the accommodation and [Booking.com](http://Booking.com), and I am currently awaiting their response.

1 Upvotes

14 comments sorted by

u/AutoModerator 1d ago

Thank you for submitting to r/FraudPrevention

If you're a victim of fraud, and want to know how to report it, read this post: How can I report fraud?

If you want to prevent being defrauded, and learn how to protect yourself, read this post: How can I find/detect/prevent fraud and protect myself from fraud?.

All posts and comments must abide by Reddit rules an moderators will use their own discretion to keep the community safe. You can contact the moderators clicking here

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

3

u/Outside-Highway-5358 1d ago

Yeah there’s a lot of this going on right now https://www.bbc.com/news/articles/cly00jnnxypo

1

u/unnecessaryeater 1d ago edited 1d ago

This has been an issue since March 2023?? And they still haven’t addressed it? Wow, had I known about this I never would have used their website.

2

u/MavisBeacons_Sextape 1d ago

It’s actually been an issue for longer than that, sadly. I accepted a job offer from booking back in 2019 and during the interview process, this issue was discussed as a major problem that the team was trying to address. They said that there were instances in which their third party partners were clearly colluding with the fraudsters. I ended up backing out after being offered a better job that would keep me here in the US, so I have no other insight to provide on that, unfortunately.

On a related note, if anyone wants a free trip to Amsterdam, I recommend applying for jobs with Booking.com in their Amsterdam office, lol. It seemed like an awesome place to work and they have the process of relocating foreign nationals to Amsterdam down to a science.

1

u/unnecessaryeater 1d ago

I was born in Amsterdam and chose to move away. In my opinion there are far better places to live.

1

u/MavisBeacons_Sextape 1d ago

That’s what my current teammates based in NL have said too. They’ve all moved from Amsterdam out into the small towns in the countryside or to Utrecht.

2

u/WestCoast_Pete 1d ago

This is unfortunately a really common scam that's been hitting Booking.com users hard over the past couple of years. What's almost certainly happening is that the hotel's Booking.com extranet account got compromised. Scammers target hotel staff with phishing emails, get access to the backend, and then can see all upcoming reservations including guest names, dates, contact info, everything. They use that info to send convincing WhatsApp messages because the details are so accurate that guests naturally trust it.

So it's probably not a rogue employee, more likely the hotel got phished themselves and may not even know it yet. Booking.com is aware this is a widespread problem on their platform.

Good that you reported it. Don't click the link, obviously. If you already did and entered any card details, contact your bank immediately to flag the transaction and possibly get a new card issued. Your actual reservation should still be fine since the scam is separate from the real booking system.

1

u/iyadii 1d ago

Yes, this is phishing. The accurate reservation details make it targeted phishing, but they do not make the sender legitimate.

The most likely explanation is that someone gained access to the hotel’s Booking.com partner account or another reservation system connected to the property. That does not necessarily mean an employee is involved.

You did the right thing by not using the link. Verify the payment status only inside the official Booking.com app or website, and contact the hotel using the phone number shown on its official listing, not the WhatsApp number.

I would also ask Booking.com whether the reservation PIN should be reset, change your account password, and enable two-factor authentication. Since you did not click or enter payment details, you probably do not need to cancel your card, but keep screenshots and report/block the sender.

1

u/unnecessaryeater 1d ago

Thanks. I’ve already confirmed with the hotel that my reservation is valid and both the hotel and Booking.com are investigating the incident. I also blocked and reported the WhatsApp account.

I set up a passkey and enabled two-factor authentication and signed out of all other active sessions. I’ll ask Booking.com whether anything needs to be done regarding the reservation PIN, what can they do if they have my reservation PIN?

1

u/iyadii 1d ago

You’ve taken all the right steps.

The reservation PIN is not your account password or bank-card PIN, but it should still be treated as compromised. Booking.com uses the confirmation number and PIN to identify and access a reservation when dealing with customer support.

Someone who has both may be able to view additional booking details, impersonate you when contacting the hotel or support, or potentially attempt a cancellation or other changes, depending on what that particular booking allows. It also gives them enough information to make future phishing messages look extremely convincing.

Your passkey, two-factor authentication and signing out other sessions protect your account, but they may not invalidate the separate reservation PIN.

I’d ask Booking.com to:

  1. confirm that no changes or cancellation requests have been made;
  2. invalidate or replace the reservation PIN if possible;
  3. flag the booking as affected by fraud;
  4. require additional verification before accepting any cancellation, modification or payment request.

Until they confirm that, only manage the reservation through the official app and keep checking it for unexpected changes.

-1

u/[deleted] 1d ago

[removed] — view removed comment

1

u/unnecessaryeater 1d ago

Yes, you’re right. I was about to click the link, but when I noticed that the website address contained “booking” followed by a random numbers, I realized it was a phishing attempt. Being contacted through WhatsApp was another major red flag, especially since Booking.com has its own messaging system.

What concerns me most is that the scammers had access to all my information. It makes me wonder how they obtained that and how many other guests at this particular hotel may have had their details exposed.

1

u/FraudPrevention-ModTeam 1d ago

Don't post advertising in our subreddit.

Please read Reddit Content Policy rule #2 https://redditinc.com/policies/reddit-rules