logo

Hackers Exploit Hotel Booking Systems to Send Fake Payment Requests to Guests

ID: b0cae596-f9be-511c-a1a6-a6cb2a438843

STIX ID: report--b0cae596-f9be-511c-a1a6-a6cb2a438843

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Researchers report a growing “Reservation Hijack Scam” targeting hotel booking workflows: attackers phish hotel staff or partners to steal credentials and access real reservation data, then send legitimate-looking, time-urgent payment requests (via Booking.com messaging, WhatsApp, SMS, email, or PDFs) that redirect victims to typo-squatted sites to harvest payment details; activity has been observed across the UK, France, Germany, the US, Brazil, and Australia, and mitigations include phishing-resistant authentication, staff training, and monitoring of guest messaging systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.