Attackers are exploiting hotel reservation systems and booking workflows in a fraud campaign dubbed the Reservation Hijack Scam, using stolen reservation details and compromised staff accounts to contact real travelers through trusted channels including Booking.com messaging, email, SMS, and WhatsApp. Researchers said the scam is especially effective because messages arrive in legitimate conversation threads or from authentic hotel accounts, making fake payment requests appear to be routine customer service. Victims are then directed to spoofed guest portals, branded PDFs, or typo-squatted payment sites designed to steal card details or induce bank transfers.
In more advanced intrusions, attackers first phish hotel employees for credentials to hospitality platforms such as Cloudbeds, or gain persistent access by tricking partners into running malicious commands that deploy a remote access trojan. Cloudbeds said observed cases were caused by credential phishing rather than a breach of its platform. The activity has been reported most heavily in the UK, France, Germany, the US, Brazil, and Australia, prompting recommendations that travelers verify payment requests only through official hotel or booking channels, while hospitality organizations strengthen phishing-resistant authentication, access controls, monitoring, and incident response.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Gen Digital published research describing the Reservation Hijack Scam as a fast-growing fraud campaign affecting hospitality workflows in regions including Western Europe, the United States, Brazil, and Australia. The report detailed tactics such as fake guest portals, spoofed payment pages, branded PDFs, and typo-squatted domains used to steal card or bank transfer details.
Cases involving Cloudbeds-connected hotel operations were reported in which stolen staff credentials were used to access reservation information and guest communications. Cloudbeds stated the incidents were caused by phishing against users rather than a breach of its platform.
In stronger variants of the scam, attackers phished hotel employees for credentials to hospitality platforms such as Cloudbeds, and in some cases used malicious commands to install remote access malware for persistent access. This gave them access to reservation data and legitimate guest communication workflows.
A fraud pattern dubbed the Reservation Hijack Scam emerged in which attackers abused real hotel reservation details and trusted communication channels to send fake payment requests to travelers. The scam used channels including Booking.com messaging, email, SMS, and WhatsApp to make the requests appear legitimate.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcecybersecuritynews.com
Open sourcegendigital.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.