logo

Booking.com Phishing Scam Targets Employees in the Hospitality Sector

ID: 387fd314-f8f2-5ff1-8b29-c0603187de59

STIX ID: report--387fd314-f8f2-5ff1-8b29-c0603187de59

Feed Name: KnowBe4 Blog

Threat Score
65/100

Date Published: 2025-03-18

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Microsoft researchers observed a phishing campaign impersonating Booking.com that targets hospitality-sector employees. The malicious pages display a fake CAPTCHA and use the "ClickFix" social engineering technique to instruct users to open a Windows Run window and paste a command (copied to the clipboard) that ultimately downloads a suite of credential‑stealing malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.