Security News > 2023 > December > Booking.com customers targeted in hotel booking scam
Scammers are hijacking hotels' Booking.com accounts and using them as part of a hotel booking scam aimed at tricking guests into sharing their payment card information.
"Customers of multiple properties received email or in-app messages from Booking.com that purported to be from hotel owners requesting confirmation of payment details for upcoming stays," Secureworks researchers warn.
"The day after the malware was executed, a hotel employee observed that multiple messages had been sent to upcoming guests from the hotel's Booking.com account. Several hours later, hotel customers started to complain that money had been taken from their accounts," the researchers noted.
The hotel booking scam targeting Booking.com customers has been going on for a while.
"As far back as March 2023, two hotels posted messages on Booking.com's partner support hub reporting that the official messaging mechanism was abused to defraud their customers. In August 2023, a third hotel contributed to the thread by including the contents of a message used to target one of its customers," Secureworks researchers noted.
There have been news reports about losses suffered by hotel guests, and extensive forum threads by victims and almost-victims sharing their experiences of having been targeted, usually via Booking.com communication channels.
News URL
https://www.helpnetsecurity.com/2023/12/04/booking-com-hotel-booking-scam/