A data breach at Booking.com is now being linked to a rise in so-called “reservation hijacking” scams, a type of fraud that’s becoming more convincing, and harder to spot.
While the breach itself involved access to booking information rather than payment details, experts warn that the data exposed could be enough to fuel highly targeted scams.
For travellers, the risk isn’t just what was taken. It’s how that information can now be used.
What is a reservation hijacking scam?
Reservation hijacking is a form of phishing where criminals pose as a hotel or booking platform and contact you about a real trip. They don’t rely on generic messages. Instead, they use genuine booking details to make their communication look legitimate.
That might include:
- The name of your hotel
- Your travel dates
- Your contact details
- Information linked to your reservation.
Because the message matches a real booking, it can feel like routine customer service rather than a scam.
Typically, the goal is to get you to:
- “Verify” payment details
- Pay a deposit or outstanding balance
- Resolve a supposed issue with your booking.
In reality, the money goes directly to the scammer.
Why this is linked to the Booking.com breach
Booking.com has confirmed that unauthorised parties accessed customer booking data, including names, contact details and reservation information. According to reporting, this type of data is exactly what scammers need to carry out reservation hijacking attacks at scale.
In the past, similar scams often relied on hacking hotel systems to send messages through official channels. That made them dangerous, but limited in scope. This breach changes that.
Criminals no longer need access to hotel accounts. With booking data in hand, they can contact travellers directly and still appear credible. Security experts have highlighted that this makes scams more precise — and more effective.
Why these scams are so convincing
Most people are used to receiving messages about bookings. Confirmations, updates, check-in details — it’s all part of the normal travel experience. Reservation hijacking exploits that expectation.
There are three reasons these scams work:
- They use real information. When a message includes the correct hotel name and travel dates, it immediately feels legitimate.
- They arrive at the right time. Messages often appear shortly before a trip, when people are more likely to act quickly.
- They create urgency. Scammers may claim there’s a problem with your booking or that action is needed to secure your stay.
That combination makes it easy to respond without double-checking.
What you should do if you’ve used Booking.com
If you’ve used Booking.com, particularly for an upcoming trip, it’s worth being cautious.
Warning signs include:
- Messages asking for payment outside the
- Booking.com platform
Requests to transfer money urgently - Links that take you away from the official website or app
- Contact from unfamiliar email addresses or phone numbers.
Even if you haven’t been contacted directly about the data breach, it’s sensible to assume your data could be at risk and take a few simple precautions. Even if a message looks genuine, it should always be verified.
How to protect yourself
A few simple steps can reduce your risk:
Be cautious with messages about your booking
If you receive an email, text or WhatsApp message about a reservation, don’t click links or use contact details provided in the message. Go directly to the Booking.com app or website and check your booking there.
Never share payment details outside official channels
Booking.com has confirmed it will not ask for payment details via email, phone, text or messaging apps. Any request to transfer money or provide card details outside the platform should be treated as suspicious.
Strengthen your account security
To protect your account:
- Change your Booking.com password
- Use a strong, unique password
- Enable two-factor authentication where possible
Keep an eye on your accounts
Monitor your bank and card statements for any unusual activity, particularly in the lead-up to a trip.
Can you make a data breach claim?
If your data was compromised in this breach, you may be able to make a data breach claim. At this stage, there’s no confirmed group action linked to the Booking.com breach. But situations like this are often monitored closely as more information emerges.
We’ll keep you updated and explain what your options might be.
Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.