A critical payment-processing flaw was reportedly exploited in Spain by a 20-year-old fraudster who obtained luxury hotel stays for €0.01 while merchants received what appeared to be legitimate payment confirmations for bookings worth tens of thousands of euros. The attack did not rely on stolen card numbers; instead, it allegedly manipulated the transaction data flow between a hotel booking site and a major payment platform so the merchant saw an approval for the full amount while the actual transferred value was only one cent. The case highlights an integrity failure in online payment validation rather than a conventional card-theft scheme.
The reporting indicates the weakness stems from a timing gap between payment authorization and final settlement, allowing the discrepancy to remain undetected until days later, after the guest had already checked out. One account puts the direct loss at more than €20,000 and says Spanish police identified the method as a new modus operandi. For security and fraud teams, the incident underscores the need for real-time reconciliation between authorized and settled amounts, stronger validation of payment notifications, and controls to ensure the amount confirmed by a processor exactly matches the amount ultimately received.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Spanish police arrested a 20-year-old alleged hacker accused of manipulating online payment flows so stays worth thousands of euros in Madrid luxury hotels were validated after only a one-cent payment. The case exposed a timing gap between payment validation and final settlement in booking and payment workflows.
A travel agency reported a fraud scheme in which luxury hotel reservations were confirmed even though only one cent was actually transferred, triggering the investigation. Reported losses from the scheme exceeded 20,000 euros.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.