Gen Threat Labs reported that more than 350 accommodations in 50 countries were tied to "Reservation Hijack" scams that used real booking details to target travelers with convincing phishing messages. The campaigns delivered fraudulent payment requests through SMS, WhatsApp, email, and in-app messages, directing victims to fake accommodation-branded payment pages. Researchers said the activity appeared organized and repeatable, citing shared phishing-page components, repeated asset paths, fake live-support chat features, and common card-validation language across multiple incidents.
The findings followed Booking.com warnings to customers that unauthorized parties may have accessed reservation-linked information and reset reservation PINs, indicating exposure of private booking data that could be used to personalize scams. Gen said the largest concentration of affected properties was in Europe—especially Germany, France, the United Kingdom, Italy, and Spain—but the activity also reached the United States and other regions. The company urged travelers to verify payment requests only through official booking channels, while accommodations were advised to strengthen MFA, account monitoring, endpoint protection, and staff phishing awareness.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Gen Threat Labs expanded its investigation into "Reservation Hijack" scams and reported evidence connecting more than 350 compromised accommodations across 50 countries to booking-specific phishing attacks. The researchers said the activity appeared organized and repeatable based on shared phishing infrastructure and tactics across campaigns.
Booking.com notified affected customers that unauthorized parties may have accessed reservation-linked information and reset reservation PINs. The notice was tied to booking-specific phishing activity targeting travelers through messages that impersonated accommodations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
gendigital.com
Open sourceskynews.com.au
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.