Here’s what’s been reported recently about Booking.com being hacked and the fallout.
Key recent developments
- A significant data breach affected Booking.com in April 2026. Attackers allegedly accessed guest booking details, including names, email addresses, phone numbers, and physical addresses, and the company confirmed unauthorized access to some guest booking information. Security PINs for affected bookings were reset as an immediate precaution. This has been linked to a rise in targeted phishing and fraud using the stolen booking contexts. [Source reports indicate Booking.com publicly acknowledged the incident and took steps to mitigate credential risk for affected bookings.][2][5][6]
- Numerous outlets and security-focused sites have described the breach as enabling highly targeted fraud, including phishing campaigns that leverage precise booking details to impersonate hotels or guests. The reported evidence suggests a broad, global impact with ongoing investigations into the exact scope and number of affected records.[4][9][2]
- Coverage also notes that the stolen data could enable “conversation hijacking” where attackers exploit knowledge of travel plans to craft convincing scam communications. Booking.com has advised customers to be wary of unsolicited messages, especially those requesting payment or asking for verification of sensitive details. PIN resets and customer notifications were among the immediate countermeasures.[5][6][2]
What to do if you were affected
- If you have a Booking.com account linked to a recent or past booking, monitor your email and phone for security notices from Booking.com, and expect possible PIN resets or credential-related prompts.[2][5]
- Be cautious of messages claiming to be from Booking.com or hotels you’ve booked, especially those asking for payments, verification details, or links to sign in. Verify any requests through the official Booking.com app or website rather than via links in messages.[4][2]
- Consider enabling additional verification on your devices and changing passwords for related accounts, particularly if you reuse credentials across services. While Booking.com reported PINs were reset for affected bookings, broader account security hygiene remains important.[6][5]
Context and ongoing developments
- This incident has sparked broader discussion about phishing risk in the travel sector and the need for stronger authentication practices across platforms. Analysts emphasize vigilance for targeted scams using real booking data.[8][4]
- Booking.com has publicly stated it took containment steps and warned customers about potential follow-on fraud, with ongoing investigations into the incident. The scope and exact impact are evolving as more details emerge.[9][2]
If you’d like, I can compile specific guidance for residents in Los Angeles or U.S. travelers, and set up a quick alert checklist to spot and report suspicious activity. I can also pull the latest updates from additional sources and summarize any new official statements from Booking.com. Please tell me your preference.[2]
Sources
Hacker haben Daten von der beliebten Buchungsplattform Booking.com gestohlen - nun nutzen die Kriminellen gestohlene Buchungsdaten für täuschend echte Zahlungsaufforderungen. Worauf Sie achten müssen.
www.news.deAllSec.sh — a real-time aggregator of cybersecurity news, vulnerability disclosures, and security research from across the web.
allsec.shHeute noch ein kleiner Sammelbeitrag rund um das Thema Cybersicherheit in Verbindung mit booking.com. Kürzlich informierte mich ein Leser über massiven booking.com-Spam und vermutete „einen…
www.borncity.comPhishing über Booking.com: Nutzer erhalten Fake-Nachrichten mit echten Buchungsdaten. Die Plattform? Reagiert kaum – und lehnt 2FA weiter ab. Hier geht's zum News-Artikel.
bearingpoint.servicesBei Booking.com wurden sensible Buchungsdaten gestohlen, die nun für präzise Betrugsversuche gegen
www.ad-hoc-news.deGästebuchungsdaten, die dem Buchungsriesen gestohlen wurden, können von Betrügern dazu genutzt werden, sich als Hotels auszugeben, um Zahlungs- und persönliche Daten zu stehlen.
www.malwarebytes.comEin schweres Datenleck bei der Reiseplattform Booking.com betrifft unzählige Nutzer weltweit. Hacker haben Zugriff auf sensible Hotelreservierungen erlangt und nutzen das Material bereits aktiv für gezielte Betrugsversuche über WhatsApp aus.
winfuture.deBooking.com gibt unbefugte Fremdzugriffe auf Buchungsinformationen zu. Betroffene Kunden werden informiert, ihre PINs aktualisiert.
news.icod.deEin Datendiebstahl bei Hotelpartnern ermöglichte Betrug über die offizielle Plattform. Die Reisebr
www.ad-hoc-news.deEin schwerer Datenleck bei Booking.com ermöglichte Zugriff auf persönliche Buchungsdaten, was zu einer Flut täuschend echter Phishing-Angriffe führte. Die Bedrohung wird durch KI-generierte Nachrichten verschärft.
borncity.com