logo

Booking.com Phishers May Leave You With Reservations

ID: d80221d0-edc3-59b9-b935-55a8d6e81898

STIX ID: report--d80221d0-edc3-59b9-b935-55a8d6e81898

Feed Name: Krebs on Security

Threat Score
70/100

Date Published: 2024-11-01

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

KrebsOnSecurity reports a widespread phishing campaign targeting Booking.com partner hotels: attackers obtained partner credentials (often via malware/infostealers), registered hundreds of phishing domains (e.g., guestssecureverification.com), and used compromised accounts or purchased access to send fraudulent payment and verification messages to customers. The article highlights marketplace activity selling hotel accounts, phishing infrastructure, and data sets, Booking.com’s move to enforce 2FA for partners, and the broader risk from services that make large-scale credential-based fraud simple and profitable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.