National CERT teams in Croatia and Slovenia warned that attackers are using stolen accommodation reservation data to run highly convincing phishing campaigns impersonating Booking.com and lodging providers. The messages, often sent from foreign phone numbers over WhatsApp and sometimes via Viber or SMS, cite real guest names, phone numbers, stay dates, and booking details to claim there is a payment problem or reservation issue, then direct victims to fraudulent websites designed to capture bank card information or induce unauthorized payments.
The warnings follow confirmed security incidents involving Booking.com and the Croatian hotel reservation provider Phobs, whose systems exposed personal, contact, and reservation data used by accommodation providers across the region. Booking.com said unauthorized parties accessed some users’ reservation information but not home addresses or payment card numbers, while SI-CERT said there is no indication financial data was stolen from Phobs; however, both incidents created enough context for realistic social engineering. CERT authorities urged travelers to verify any payment request only through Booking.com’s official app or website or by contacting the accommodation provider through an independent channel, and advised anyone who submitted card data to notify their bank immediately and report financial theft to police.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CERT and SI-CERT warned that stolen reservation details were being used in phishing campaigns impersonating Booking.com or accommodation providers. The scams commonly used WhatsApp, and sometimes Viber or SMS, to reference real bookings and lure victims to fraudulent payment pages to steal card data or induce payments.
SI-CERT reported a security incident affecting Croatian reservation system provider Phobs, used by many accommodation providers in Slovenia and the wider region. Exposed data reportedly included guests’ personal and contact information and reservation details, with no current indication that payment card data was stolen.
Booking.com confirmed that unauthorized third parties accessed reservation information for some users. The company said attackers obtained personal data and booking details, but not home addresses or credit card numbers, and it took containment steps including changing PINs for compromised reservations and notifying affected users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cert.hr
Open sourcecert.si
Open sourcecert.hr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.