Hackers Exploit Hotel Booking Systems to Send Fake Payment Requests to Guests
ID: b0cae596-f9be-511c-a1a6-a6cb2a438843
STIX ID: report--b0cae596-f9be-511c-a1a6-a6cb2a438843
Feed Name: GBHackers
Researchers report a growing “Reservation Hijack Scam” targeting hotel booking workflows: attackers phish hotel staff or partners to steal credentials and access real reservation data, then send legitimate-looking, time-urgent payment requests (via Booking.com messaging, WhatsApp, SMS, email, or PDFs) that redirect victims to typo-squatted sites to harvest payment details; activity has been observed across the UK, France, Germany, the US, Brazil, and Australia, and mitigations include phishing-resistant authentication, staff training, and monitoring of guest messaging systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
