Spanish National Police arrested a 20-year-old Spanish national accused of hacking an online hotel booking workflow to fraudulently reserve luxury hotel rooms for €0.01 by manipulating the payment validation process. Authorities said the attack altered how an electronic payment platform’s validation was confirmed so bookings appeared fully paid, while only a nominal charge was actually processed; police described it as the first known case they have seen using this specific method.
Investigators opened the case after an unnamed booking website reported suspicious activity; the transactions initially looked legitimate and the discrepancy was only detected days later when the payment platform transferred the actual paid amount to the hotel. Police said the suspect repeatedly used the technique at a luxury Madrid hotel, causing losses exceeding €20,000, and was arrested while staying on a four-night reservation valued at about €4,000; authorities also allege he consumed minibar items and sometimes left those charges unpaid.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following the arrest, the suspect was presented to judicial authorities on suspicion of computer fraud. Police said the investigation remained ongoing into repeated fraudulent bookings, unpaid minibar charges, and the broader impact on affected hotels.
Spanish National Police arrested the 20-year-old man while he was staying at a luxury hotel in Madrid on a four-night reservation worth about €4,000 that allegedly cost him only €0.01. Authorities said the scheme exploited a booking website’s payment validation flow, enabling repeated stays and losses exceeding €20,000 to at least one hotel.
After technical analysis of the manipulated payment-validation activity, Spanish police identified a 20-year-old Spanish suspect within four days of the initial complaint. Investigators described the case as complex and the method as a previously unseen or novel attack technique.
A travel or booking agency reported suspicious activity involving fraudulent luxury hotel reservations to Spanish National Police after noticing discrepancies in payment processing. Multiple sources place the report on 2026-02-02, marking the start of the investigation.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcebitdefender.com
Open sourcetechxplore.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.