NEWS
The Booking.com WhatsApp Scam Still Knows Your Dates
Booking.com already requires partner two-factor login and says it never uses WhatsApp, yet hotel-side leaks still feed card-check texts with real stay dates.
A traveler who booked a hotel in France through Booking.com got a WhatsApp asking to validate a card in 12 hours. The ping already had the name, the stay dates, and the hotel, and the stay was already paid.
The hotel confirmed the note was a scam. Booking.com still tells partners to lock the login and tells guests it never uses WhatsApp. The text still reads like the front desk.
The WhatsApp Already Had the Stay Dates
The tell is not a misspelled brand. It is a real reservation, replayed on a channel the guest did not use to book. The French-hotel case used WhatsApp Business accounts. The traveler said the same script arrived from numbers in Tanzania and Brazil.
The ask was the usual one: keep the booking by checking the card, through a link, inside 12 hours. A July 9, 2026 post from a French traveler described the same clock, the same hotel-level detail, and a copied Booking.com pay wall after the tap.
WHAT THE PING ALREADY KNEW
- The stay: Property name and dates matched a real Booking.com reservation that had already been paid.
- The guest: The greeting used the name on the booking, which is why the note survived the first glance.
- The fuse: A 12-hour deadline to “validate” a card or lose the room, a pressure beat Gen Digital also sees at 24 or 48 hours.
- The channel: WhatsApp Business, not the in-app inbox, which is where a genuine Booking.com thread would sit.
Scripted replies can land so fast they feel like a bot. That speed is part of the costume. A live clerk is rarely sitting on WhatsApp waiting to re-check a card the platform already took.
Partner Logins Are Where the Leak Starts
Booking.com has said its own core systems were not the hole. The useful data sits in hotel partner accounts, the Extranet logins properties use to see who is coming and to message them.
On April 13, 2026, the company emailed guests that “unauthorized third parties may have been able to access certain booking information associated with your reservation.” It reset reservation PINs and did not publish a headcount. Sage Hunter, Booking.com’s communications lead, gave the company’s line in one block.
At Booking.com, we are dedicated to the security and data protection of our guests. We recently noticed some suspicious activity involving unauthorized third parties being able to access some of our guests’ booking information. Upon discovering the activity, we took action to contain the issue. We have updated the PIN number for these reservations and informed our guests
Sage Hunter, communications lead, Booking.com
A new PIN stops someone walking into the live booking with the old code. It does not unsay a name, a phone number, or a check-in date that already left the building. That is the packet a fake hotel WhatsApp needs.
WHAT THE APRIL 2026 NOTICE SAID WAS EXPOSED
| Data | In the guest email | Why a fake hotel ping wants it |
|---|---|---|
| Full name | Yes | The greeting matches the reservation |
| Email address | Yes | A second copy of the same lure |
| Postal address | Yes | Extra proof the sender “knows” you |
| Phone number | Yes | The WhatsApp can be sent at all |
| Notes shared with the property | Yes | Special requests make the tone feel in-house |
| Card numbers | No; the company said financial data was not taken | The scam tries to collect the card from the guest instead |
The April mail also told people the company will not ask for sensitive details or bank transfers. The WhatsApp that follows is built to ignore that sentence.
Two-Factor Codes Are Already Mandatory
The common complaint is that Booking.com will not force hotels to lock their logins. Its own partner help page now says the opposite. During registration, mandatory two-factor setup for partners is required, and a sign-in uses the password plus a PIN sent to a trusted device.
The same page says staff may be asked for that second code more than once in 24 hours. It also tells partners to make contact within 24 hours if they handed a sign-in or a 2FA PIN to someone they should not have trusted. That sentence is a confession in plain language: the extra code can still be read out to a stranger.
Booking.com even argues that SMS codes are the weaker option, because a text can be read by someone else, while an app-generated TOTP expires fast. Plenty of small properties still live on the SMS path. A clerk who is already logged in, or who pastes a “fix” into the same PC, does not need to beat a lock that has already opened.
How ClickFix Gets Past the Login Prompt
Hotel staff get a fake Booking.com email about a last-minute booking, a bad review, or an account check, then a fake CAPTCHA tells them to paste a command into Windows, and that step loads malware that steals the Extranet session after the person has already typed the extra PIN. Microsoft Threat Intelligence, in a March 13, 2025 note on a ClickFix campaign tracked as Storm-1865, said it had seen those staff-facing mails from December 2024 and that the wave was still going as of February 2025. The same cluster had already aimed at hotel guests in 2023.
Gen Digital later described partners being pushed to install a “mandatory security update” that was in fact a command to load a remote access trojan. Once that foothold is in, the attacker can read who is arriving and write to them as the hotel. Sekoia, a French security firm, described a related hotel campaign running from April 2025 into early October 2025, with stolen partner logins sold on crime forums.
THE STAFF-TO-GUEST PATH ON THE RECORD
- 2023: Microsoft says Storm-1865 is already aiming Booking.com-themed malware at hotel guests.
- December 2024: The same cluster shifts toward hotel staff, using fake Booking.com mail and ClickFix prompts.
- March 13, 2025: Microsoft publishes the Storm-1865 write-up and says the staff campaign is still active as of February 2025.
- April 2025: Sekoia dates a hotel-partner harvest that runs at least into early October 2025.
- March 25, 2026: Gen Digital publishes its reservation-hijack paper, including WhatsApp, SMS, email, and in-platform chat.
- April 13, 2026: Booking.com emails guests, resets PINs, and still will not say how many people were in the batch.
- August 29 to September 1, 2026: Booking.com’s public account is still telling individual guests it does not use WhatsApp.
Two-factor login on the website does not inspect the clerk’s keyboard. The session that follows is what gets stolen.
The Hotel Called It Someone Else’s Mess
In the France booking, the guest took the WhatsApp to the property. The hotel said the leak was not its problem. That answer is the other half of the company’s line that the hole sits in partner accounts rather than in Booking.com’s own vault.
Both can be true in a narrow sense. The clerk’s PC is not Amsterdam. The guest’s name still left through a login the hotel used to run the room. A later check with a property is one of the few tests that still works. In late August, a traveler who had been asked to settle a “balance” to confirm an old reservation emailed the hotel and was told the WhatsApp was not theirs.
Small hotels run lean. One inbox, one laptop, one person who also answers Booking.com mail about reviews. That is the machine ClickFix is built for. Telling the guest to be careful, after the dates have already been copied, is not a patch. It is a shrug.
Western Europe Keeps Showing Up in the Samples
The France stay sits in the band Gen Digital flagged. In the reservation hijack pattern mapped by Gen, the busiest samples were in the United Kingdom, France, and Germany, with the United States, Brazil, and Australia also in the mix. Brazil appearing in that list matches the traveler’s claim that one of the Business accounts sat on a Brazilian number, though that pair of countries is still this case, not a census.
Norton researchers, in work published through Gen’s consumer brand, later counted at least 350 hotels, motels, rentals, and guesthouses across 50 countries in scam messages they reviewed. Those properties had room for around 80,000 guests at peak. Norton’s team has been clear that the list is a floor from the lures they saw, not a full map of every taken inbox.
WHERE THE SAMPLES CLUSTER
- The countries: Gen Digital’s highest activity sat in the UK, France, Germany, the US, Brazil, and Australia.
- The floor count: Norton’s later pass named at least 350 properties in 50 countries.
- The rooms: Those 350 places could hold around 80,000 guests at peak, which is a capacity figure, not a victim tally.
- The pipes: The same lure moves over WhatsApp, SMS, email, and Booking.com’s own guest chat once a partner account is in someone else’s hands.
When the hijack is strong enough, the fake request can sit inside a real Booking.com thread. The guest is not looking at a random number. They are looking at the same conversation they already used to ask for a late checkout.
Booking.com Still Repeats the WhatsApp Warning
Booking.com has said for years that it will not ask a guest to share payment details by email, chat, text, or phone. On August 29, 2026, its public account told another worried guest the same thing in shorter form: the company does not communicate on Telegram or WhatsApp, and people should stop talking to the sender.
Hi there, we regret to hear about your experience. Unfortunately, there are people who fraudulently use the https://t.co/1kiKvXFB3w name to impersonate our company and take advantage of our guests and potential employees. Please note that we do not communicate via apps such as…
— Booking.com (@bookingcom) August 29, 2026
It was still repeating that line on August 31 and September 1. Guests who booked Europe stays in late August were still getting the card-check ping anyway. One of them noted that WhatsApp was the giveaway, and that the warning is easy to miss inside the app. WhatsApp warnings on payment and card asks say the same thing in different clothes: a stranger who wants a card number, a tap, or a rush job is running a scam, even if they already know your name.
WHAT WE KNOW
- The leak path: Hotel partner logins and staff PCs, not a published break of Booking.com’s central vault.
- The guest packet: Names, mails, phones, addresses, stay details, and property messages, with card numbers left for the follow-up ping to harvest.
- The live lure: WhatsApp (and SMS, email, or in-app chat) quoting a real stay and a short card-check deadline.
WHAT IS UNCONFIRMED
- The headcount: Booking.com has not said how many guests sat in the April 13, 2026 mail, or how many partner accounts were in that batch.
- This France stay: There is no public tie between that one hotel and the April notice.
- The Tanzania-Brazil pair: Those origins are what this traveler saw, not a proven standard routing.
The company can require the extra PIN, reset the booking code, and keep posting that it does not live on WhatsApp. The clerk’s PC can still hand over the stay list. Until that login is treated as part of the product, the next message will still know the dates.
-
BUSINESS3 weeks agoConsumer Sentiment Falls to 51.7 as Future Outlook Darkens
-
NEWS3 weeks agoPluto’s Heart Glacier Still Pushes Liquid Nitrogen Upward
-
NEWS3 weeks agoUMMC Will Rebuild 30-Year-Old Cancer Labs With $2.4 Million
-
NEWS2 weeks agoWater-Shedding Coatings Charge the Drops That Pierce Them
-
NEWS1 week agoAn MRI Score Times Decline in Early-Onset Alzheimer’s
-
ENTERTAINMENT2 weeks agoNetflix Weighs Hosting Peacock and Fox One in Its App
-
ENTERTAINMENT2 weeks agoPeacock Restages Hilary Banks’s 30-Year New York Exit
-
GAMING2 weeks agoGTA 6’s 80-Hour Run Counts Goals That Change the Story
