Booking.com Phishing Scam 2026: How Reservation Hijacks Work and How Hosts Stop Them
A few days before check-in, a WhatsApp message lands on a guest’s phone. It looks like it came from the hotel. The guest’s name is right. The property name is right. The dates match the confirmation sitting in their Booking.com app. The message says there is a payment problem, the reservation is “pending,” and they have a short window to tap a link and confirm the stay.
That is not the hotel. It is a Booking.com phishing attack — a reservation hijack built on real booking data.
German tech magazine c’t reconstructed this pattern in issue 17/2026 in the article “Abgebucht” by Markus Montz, after speaking with Booking.com’s head of IT security, Predrag Vuckovic, and with hotel managers who have been on the receiving end. The same wave hit English-speaking travelers in April 2026, when Booking.com began emailing guests that unauthorized parties had viewed reservation information.
If you host on Booking.com, Vrbo, or Airbnb in Houston, this is not a guest-only problem. Criminals get in through the property’s own back-office login. That is why Home CoHost treats OTA account security as part of booking management and guest communication, not as an IT afterthought.
How Booking.com phishing actually works
The scam does not start with a random spam email. It starts with a compromised extranet account — the partner dashboard hotels and vacation rentals use to manage reservations on Booking.com.
Once attackers are inside that dashboard, they can see live bookings: guest name, phone number, email, stay dates, and the reservation PIN. They then message the guest off the platform, usually on WhatsApp, SMS, or email, while impersonating the property. Because the details are real, the message survives a first glance.
c’t documented a typical lure. The booking is “pending confirmation,” a countdown is running, and a link — often a look-alike domain that has nothing to do with Booking.com — asks the guest to “review reservation details.” Click it and the guest lands on a fake site built to steal card data, trigger a second payment, or, in worse cases, enroll the victim’s Apple Pay or online banking.
Norton’s threat research team has called this playbook a reservation hijack. In reporting cited by c’t, Norton estimated that a concerted campaign hit about 350 properties and as many as 82,000 guests at once.
Why April 2026 put the scam on the map
Booking.com confirmed in April 2026 that unauthorized third parties had accessed booking information for some guests. The company said it reset reservation PINs and notified affected travelers. It also said payment card data was not taken from its own systems, and that physical mailing addresses were not in the accessed set.
What was taken is more useful to a fraudster than a raw card number: identity plus itinerary. With those two pieces, a scammer can write a message that feels like routine pre-arrival ops.
BBC News, Malwarebytes, and Heise all covered the same incident. Booking.com did not publish a full victim count. The company has a longer history with partner-side compromises. According to c’t, Booking.com found and blocked 26,000 compromised extranet accounts in 2025 before those accounts could do more damage, and its machine-learning systems flagged about 14 million fraudulent transaction attempts in the same period.
How criminals get into the property dashboard
They rarely “hack Booking.com” in the Hollywood sense. They hack the people who log into Booking.com.
Vuckovic told c’t that hotel staff are an easier target than other industries because they are trained to be helpful. The social-engineering script is consistent:
- Night phone calls pretending to be an emergency, a lockout, or “IT support”
- Fake reception or vendor messages that rush someone into clicking
- Emails with malware attachments that steal extranet credentials
- Fake “computer fix” prompts — the ClickFix-style campaigns Microsoft has tracked against hospitality staff
Two-factor authentication on the Booking.com extranet is now mandatory, according to the company. Attackers still try to talk staff out of the second factor, or steal session cookies so they never need the password again. After that, they can run spear-phishing against every upcoming arrival.
c’t notes that WhatsApp sits outside Booking.com’s security perimeter, which is exactly why criminals prefer it. The same gap exists on Airbnb and Vrbo if you take the conversation to a personal cell number and then send a payment link.
What Booking.com says it is doing
Booking.com describes its response as prevention, detection, and reaction:
- Mandatory two-factor authentication on extranet logins
- Round-the-clock monitoring of logins and of guest messages leaving the extranet
- Internal machine-learning models trained on both successful and failed attacks
- Sharing attack indicators with other travel companies, including competitors
- Warning partner staff and guests when a specific incident is confirmed
After the April 2026 event, Booking.com said it updated PINs on affected reservations and messaged guests. Vuckovic also told c’t that attackers did not reach Booking.com’s internal platform systems.
Hardware security keys (FIDO2) would make this class of phishing much harder. c’t points out that rolling those out across millions of partner accounts would cost money. Given Booking.com’s 15 to 20 percent commission, hotel managers interviewed for the piece said they expect a stronger security floor as a basic service.
Where hotel managers say the platform still falls short
Hotel operators interviewed for the c’t piece said they are often told about a compromised login very late — sometimes after guests have already been contacted. Some said they still would not have been warned as quickly as they were in April 2026.
There is a legal angle in the EU. GDPR requires Booking.com to notify affected people after a personal-data incident. c’t reports that Booking.com already tried, in 2019 in the Netherlands, to argue it did not have to notify every affected property. Several managers still doubt the company is telling every partner whose guests were in a stolen booking file.
That gap matters in Houston as much as it does in Europe. If you list on Booking.com, you are part of a network Booking.com put at about 4.4 million properties in more than 220 countries by the end of 2025. Criminals treat that network as a hunting ground. Your listing is a door.
How guests can spot a Booking.com phishing message
Give this list to every arrival. It is the guest-facing version of what c’t recommended, rewritten for U.S. travelers and short-term rental stays:
- No OTA will ask you to finish a payment on WhatsApp, SMS, or a random link. Booking.com, Airbnb, and Vrbo already have your payment method on file for a confirmed stay.
- Open the official app yourself. Do not use the link in the message. If the reservation is paid and confirmed in the app, ignore the panic note.
- Inspect the link. If the domain is not booking.com (or airbnb.com / vrbo.com), it is fake. The example in c’t used a “stay-home” subdomain that had nothing to do with the platform.
- Almost-right details are still a no. A wrong country code, a slightly off booking number, or a property name that is close but not exact is a tell.
- Call the property on the number from your original confirmation, not from the suspicious message. Ask whether they sent it.
- Turn on 2FA or passkeys on your Booking.com account. Do not reuse that password anywhere else.
- If money already moved, freeze the card, tell the bank it was fraud, and report it to both the platform and the property.
The same rules apply if the message claims to be from Airbnb, Expedia, or “the front desk.” c’t‘s closing advice is blunt: never leave the booking platform to talk to the property, and if you want to cut one phishing path entirely, book the hotel directly — which is often cheaper anyway.
What Houston hosts must lock down on every OTA
This is the part most guest-facing explainers skip. If you run a short-term rental, you are the attack surface.
1. Treat the extranet like a bank login
Use a unique password. Turn on passkeys or a hardware security key (FIDO2) if the platform offers them. Never share one Booking.com login across a cleaner, a virtual assistant, and the owner. Give each person their own access, and revoke it when they leave.
2. Ban off-platform payment talk
Your house rules and pre-arrival messages should say, in plain English: we will never ask you to pay by WhatsApp, Zelle, Cash App, wire, or a “verification link.” If you get that message, it is not us. Put that sentence in the booking confirmation so the guest has something to compare against the scam.
3. Keep guest communication on the platform
Stay inside Airbnb, Booking.com, or Vrbo until after check-in, and even then prefer the in-app thread. The moment you move to a personal cell number, you lose the platform’s fraud tools. That is also why a tight automated guest communication workflow beats ad-hoc texts.
4. Watch for PIN-reset and “pending” emails from the OTA
If Booking.com resets a reservation PIN, assume someone tried to use that booking. Tell the guest through the official inbox, not WhatsApp. Confirm the stay is still paid and the dates have not changed.
5. Separate devices and stop night-shift improvising
Do not run partner dashboards on the same laptop that opens random attachments. Night-shift social engineering still works on tired people. A dedicated tablet or locked-down browser profile for OTA logins is cheap insurance.
6. Put 2FA on the channel manager, not only on Booking.com
A stolen Guesty, Hostaway, or Hospitable login can dump every OTA at once. The channel manager is the master key. Protect it like one.
7. Tell guests the real playbook once, early
A booking-confirmation note that says “we only message you inside Airbnb or Booking.com, and we will never send a payment link” stops a surprising number of hijacks. Home CoHost builds that line into the guest workflow so it goes out on every reservation, not only when someone remembers.
If you also list on Vrbo and Booking.com to diversify off Airbnb, security has to travel with the extra calendars. More channels means more extranets. Pair this with a deliberate channel plan — see our guide on expanding beyond Airbnb with Vrbo and Booking.com — instead of turning on every OTA with the same reused password.
Why this scam is a review and insurance problem, not only a guest problem
A hijacked reservation does not just steal a guest’s card. It creates:
- Chargebacks and “I already paid” disputes against the property
- Angry reviews aimed at the host, not the criminal
- Calendar chaos if a scammer cancels or modifies the booking
- Trust damage that shows up in search ranking on the OTA
For a Houston co-host managing multiple properties, one compromised partner login can touch every upcoming arrival on that channel. That is why we treat OTA account security as part of daily operations, next to turns, restocks, and guest messages.
FAQ: Booking.com phishing and reservation hijacks
Is Booking.com phishing still happening in 2026?
Yes. The April 2026 incident was a spike, not the start. Partner-extranet phishing has been a running problem for years, and c’t‘s reporting shows it is still active. Fake hotel WhatsApp messages with real booking details remain the most common guest-facing version.
Did Booking.com leak credit cards?
Booking.com says payment data was not taken from its systems in the April 2026 incident. The scam still steals cards later, from guests who click the fake payment link or hand over Apple Pay.
Can this happen on Airbnb?
Yes. Any OTA with a partner dashboard can be abused the same way. Airbnb, Vrbo, and Expedia are named in the same c’t advice: never leave the platform to “confirm” a booking, and never send payment details to a link that arrived by WhatsApp.
What should I do if a guest says they got a fake payment text?
Reply in the official inbox. Confirm the reservation is already paid. Tell them not to tap the link. If they already paid, have them contact their bank and the platform, and document everything. Then check whether your own extranet login looks normal — new devices, new message templates, changed PINs.
Should guests just book the hotel directly?
c’t notes that booking direct can be cheaper and removes one phishing path. For short-term rentals, the practical move is: keep the reservation where it was made, and never move payment off that platform.
Get help locking this down
Managing guest communication, bookings, cleaning, and OTA logins at the same time is how small mistakes become expensive ones.
Home CoHost provides professional Airbnb cohosting and short-term rental management in Houston. We keep guest messages on-platform, lock down partner dashboards, and handle the daily details so owners are not one rushed WhatsApp reply away from a hijacked stay. Contact us for professional Airbnb cohosting, or see the full service list.
Reporting in this article draws on Markus Montz, “Abgebucht,” c’t 17/2026, pp. 16–17 (Heise); the related Heise online feature published 23 July 2026; BBC News coverage of the April 2026 Booking.com incident; and Malwarebytes’ April 2026 analysis. Booking.com’s own guest notifications from April 2026 are the source for what data the company says was and was not accessed.