logo

That 'angry guest' email from Booking.com? It's a scam, not a 1-star review

ID: 69ae8804-c23f-5ee2-9350-212d50d4f0db

STIX ID: report--69ae8804-c23f-5ee2-9350-212d50d4f0db

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-03-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft Threat Intelligence describes an ongoing, multi-region phishing campaign attributed to 'Storm-1865' that impersonates Booking.com to target hospitality employees; attackers use links or PDFs that lead to fake CAPTCHA pages (ClickFix social engineering) instructing victims to paste a command into Windows Run, which downloads credential- and keystroke-stealing malware used for financial fraud and theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.