Travel Phishing Scams Surge 122%: What the Booking.com Breach Means for Merchants

The Phishing Threat Hitting Travel Merchants Where It Hurts

Travel companies have spent years building trust with customers. A pair of fresh reports suggests criminals are working overtime to exploit that trust — and the damage is landing squarely on merchants and operators.

Check Point Software Technologies documented this week that travel-sector cyberattacks have surged 122 percent since 2023, with fake Booking.com portals, counterfeit Airbnb listings, and spoofed airline check-out pages driving the bulk of it. The finding lands just months after Booking.com itself disclosed that unauthorized actors had accessed guest reservation data — including names, email addresses, physical addresses, and booking details — by compromising the hotels that use its platform.

How the Booking.com Breach Fuels a Merchant Nightmare

Booking.com began notifying affected customers on April 13, 2026. The breach did not originate from a flaw in Booking.com’s own systems. Instead, criminal actors targeted hotel partners directly using a technique called ClickFix phishing, which tricks hotel employees into installing malware by disguising it as a computer fix, according to Microsoft research. Microsoft attributes the campaign to a group it tracks as Storm-1865.

Once inside a hotel’s system, attackers pulled reservation data for Booking.com guests. That information is now in criminal hands. The implications are immediate and concrete. Scammers use that data to send guests messages that look identical to legitimate hotel communications, requesting payment verification or additional credit card details to “secure” a reservation.

The playbook is disturbingly effective. A UK Action Fraud report recorded 532 Booking.com-related scam reports between June 2023 and September 2024, with victims losing a reported 370,000 British pounds (approximately $470,000). Those numbers are likely a fraction of actual losses, since many incidents go unreported.

The Industry’s Third-Party Exposure Problem

The Booking.com incident is not isolated. It is the latest in a pattern of breaches hitting travel companies through their supply chains rather than through their own defenses.

In January 2026, Eurail disclosed a breach that exposed passport numbers, addresses, and in some cases photocopies of identification documents and health data. KLM and Air France had customer data stolen in August 2025. Hertz, Dollar, and Thrifty were all caught in the Cl0p gang’s exploitation of the Cleo file transfer software, with criminals making off with drivers’ license data and credit card information.

What connects these incidents? In every case, attackers found a point of entry through a third party — a hotel partner, a software vendor, a franchise operation — rather than attacking the travel company’s core systems directly. The travel industry’s sprawling supply chain, with its mix of franchised properties, independent partners, and third-party booking platforms, creates a wide attack surface that criminals are increasingly exploiting.

For merchants and operators, this is the real takeaway. Your own security posture may be airtight, but if your distribution partners, booking platforms, or property management vendors have weaker controls, your customer data and your reputation are only as safe as their weakest link.

What Travel Merchants Need to Watch For

The fraudsters running these schemes are not sending obvious phishing emails from sketchy addresses. They are sending messages through the same channels your customers use to manage their bookings. They know the reservation details. They know the property name. They know the check-in date. That makes the social engineering nearly impossible for an untrained traveler to spot.

Booking.com has published guidance noting that if there is no pre-payment policy or deposit requirement in the original booking confirmation, any request to pay in advance to secure a reservation is likely a scam. Guests should check their original confirmation email for what they actually owe, contact the property directly using contact information they can independently verify, and monitor bank statements for unexpected charges.

For travel merchants and operators, the advice runs parallel. Audit your third-party platform access and credentials. Train front desk and reservations staff on phishing recognition. Treat every vendor login as a potential attack vector. And have a customer communication plan ready before a breach happens — because the window between a partner getting compromised and criminals targeting your customers can be measured in hours.

The Bottom Line

The 122 percent rise in travel phishing attacks is not a statistic. It is a business risk that is landing in the inboxes and phones of your customers right now. The Booking.com breach gave criminals a supply of high-quality reservation data, and they are using it. For merchants and operators in the travel space, the uncomfortable truth is that your exposure to fraud is only partly in your own hands. The rest lives with every partner, platform, and vendor you rely on to run your business.

Sources: Check Point Software Technologies (blog.checkpoint.com), Malwarebytes Threat Intelligence, Microsoft Security Blog, The Guardian / Action Fraud UK, The Register

Editor

With decades of combined experience spanning all facets of the travel and merchant processing industries, our editorial team brings unparalleled insight to Travel Merchant News. Our expertise encompasses every angle of the travel sector, from seasoned travelers who have explored the world to travel operators who have built and managed successful tourism businesses. On the merchant processing side, we've worked extensively with payment solutions tailored specifically for the travel space, understanding the unique challenges and opportunities that travel businesses face in payment processing, transaction management, and financial operations. This comprehensive knowledge allows us to deliver content that truly speaks to the needs of travel professionals navigating the complex intersection of travel services and merchant solutions.

More From Author

Visa and Mastercard Are Betting Everything on Agentic AI for Travel Payments

Airbnb’s Fintech Gambit: What the Cancel-for-Any-Reason Feature Means for Hosts and Operators

Leave a Reply

Your email address will not be published. Required fields are marked *