Booking Holdings—Booking.com data breach exposed guest booking details, fueling 'reservation hijack' phishing scams
Booking.com confirmed that unauthorized third parties accessed customer data including names, email addresses, phone numbers, and reservation details (financial information and postal addresses were not affected). Within about two weeks, security researchers observed criminals using the stolen booking details to run 'reservation hijack' phishing scams via WhatsApp and other channels, impersonating hotels with real reservation data to trick guests into sending money. Booking.com updated PIN numbers for affected reservations and notified customers, but declined to disclose how many customers or which regions were affected.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Consumer Protection | -against | secondary | -0.50 |
| Data Security | -against | primary | -1.00 |
| Overall incident score = | -0.664 | ||
Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.59)
Evidence (1 signal)
Booking.com confirmed unauthorized access to guest data; BBC/Norton documented follow-on phishing scams
Booking.com confirmed unauthorized third parties accessed guest names, emails, phone numbers, and booking details. Within about two weeks, BBC and security firm Norton documented 'reservation hijack' phishing scams using the stolen data.