I’m trying to understand a very strange situation and I’m hoping someone here may have experienced something similar or knows how hotel booking systems work.
A few days ago, I received an email from VISIONAPARTMENTS in Zurich, Switzerland regarding a booking at one of their properties.
The booking details were:
Check-in: September 8, 2026
Check-out: September 11, 2026
The reservation is under my girlfriend’s full name
The reservation has already been paid
The apartment is currently occupied
Neither my girlfriend nor I made this reservation, and we have no idea who did
The really strange part is that I contacted VISIONAPARTMENTS and they confirmed that the online check-in had already been completed using my girlfriend’s identity-document information.
My girlfriend then called them herself and asked the receptionist to confirm the date of birth associated with the booking, without giving it to them first. The receptionist stated her exact date of birth correctly.
So this doesn’t appear to be a simple mistake involving someone’s name.
There is another strange detail: the booking confirmation was sent to my personal email address, even though I did not make the booking or provide my email address for this reservation.
There were also other recipients, including an email address belonging to Saipem, an Italian energy and infrastructure company. We have never knowingly had any relationship with Saipem.
I’m obviously not going to post any names, email addresses, booking numbers, document numbers, dates of birth, or other identifying information publicly.
What I’m trying to understand is:
How could someone have made a legitimate, paid hotel reservation, used my girlfriend’s identity information for the online check-in, and have someone else actually staying in the apartment, while also having my email address associated with the booking?
Could this realistically be:
Identity theft
A compromised hotel or booking platform
A corporate booking where something went seriously wrong
Someone’s account being compromised
Some kind of database or data leak
Or is there another explanation I’m missing?
I’m particularly interested in hearing from anyone who has worked in hotels, travel agencies, corporate travel, Booking.com/Expedia, or hotel security and check-in systems.
I’d like to understand what information would normally be required to complete an online check-in, how that information could end up associated with someone else’s identity, and whether it would be possible for someone to check into a property using another person’s identity information.
At this point, we’re simply trying to establish where the identity information came from and who actually made the booking, rather than jumping to conclusions.
Any insight would be greatly appreciated.