Skip to content
>_ITDITDWeb Security Platform

Security Guides

Correct booking details don't prove a message is real — the Booking.com reservation data access and how to spot fake property messages

In April 2026 Booking.com told guests that unauthorized third parties may have accessed some booking information, and reset reservation PINs. How to check fake 'property' messages asking for card details or payment links inside the official app.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 10 min read

For: anyone who has booked accommodation on Booking.com — upcoming or past stays. This article is based on Booking.com's notice to guests and its spokesperson's statements (as published by news outlets) and the company's official safety guidance. It does not cover attack methods.

What guests should do today

1

Don't open the link, don't pay on the spot

"Re-confirm your card to keep your reservation." "Pay within 24 hours or your booking will be cancelled." Booking.com's safety guidance names these urgent requests to (re)share payment information as the typical pattern, and warns that such messages often include convincing details about the dates and cost of your stay. That applies to email, text, WhatsApp and phone calls alike. First: don't open the link, don't type anything, don't pay. You'll check on your own terms in the next step.

2

Open the official app yourself and look at the booking's payment policy

Don't follow the message's link. Open the Booking.com app from your home screen (or the official site from your own bookmark) and go to your booking. Look at the payment policy in the confirmation: whether prepayment is required, how you pay, and any damage deposit. Booking.com says it will never ask for a bank transfer that differs from the payment policy in your booking confirmation, and never ask you to share card details by email, phone, text or WhatsApp.

3

If the request isn't in the policy, that alone is enough to call it a scam

Compare. If the message asks for a prepayment the policy doesn't mention, re-entry of your card details, payment on an outside site, a transfer to a personal account, or payment in gift cards, don't do it, no matter how accurate the rest is. Booking.com states plainly: if you're asked to pay for something that isn't in the policy, don't send it, and no legitimate transaction requires gift cards. If a property insists on moving the conversation off the Booking.com platform, the company recommends contacting customer service.

4

When unsure, ask customer service from inside the app

If you can't decide, contact customer service through the app or the official website, never through a phone number or link in the message. According to Booking.com, customer service will only ever ask for your reservation ID and reservation PIN, and will never ask for your account password or card number. If your booking's PIN was updated in this incident, check the new PIN in the app.

5

Already entered your details? Call your card issuer, tell Booking.com, change your password

Booking.com's guidance has three parts: contact customer service immediately and report that you may have been scammed; reset your account password and enable two-factor authentication; and contact your bank or payment provider to block the card, issue a new one, and flag any charges you don't recognize. Your local consumer or fraud reporting service can also help.

6

Turn on two-factor authentication and stop reusing passwords

Passwords are not listed in the notice. But someone who knows your booking can still send a "log in to check your reservation" message. With two-factor authentication, typing your password into the wrong page does not immediately hand over your account (see choosing multi-factor authentication). If you reuse the password elsewhere, split it up with a password manager.

① A message claiming to be the property or Booking.com arrives

Correct hotel, dates, price, name → don't decide here

↓

② Skip the link, open the official app yourself

Your booking → payment policy (prepayment, payment method, deposit)

↓

③-A Not in the policy

Card re-entry / pay via link / transfer / gift cards → refuse. Ask from inside the app if worried

③-B Matches the policy

Pay through the app's own flow. Still don't use the message's link

Judge by whether the request matches the booking confirmation you opened yourself, not by how accurate the message is. A correct hotel, date and price are left out of the decision.

What happened (from Booking.com's notice and statements)

The following is based on Booking.com's email notice to guests and its spokesperson's statements, as published by news outlets. As far as this site could check on September 30, 2026, Booking.com's own website and newsroom carry no dedicated notice about the incident.

What Booking.com disclosed (April 2026)
What happened
It noticed suspicious activity involving unauthorized third parties being able to access some guests' booking information
Information possibly accessed
Per the notice: booking details, names, email addresses, phone numbers, addresses, and information shared with the property through the platform (outlets describe the "addresses" item differently)
Financial information
The spokesperson said it was not accessed
Company response
After discovering the activity it took action to contain the issue, updated the PINs of the affected reservations and emailed the guests
Scale
Not disclosed (the company says affected guests were notified individually)
Timing and cause
Not disclosed

How to read it: more is unknown than known

Booking.com has not said how many guests were affected, since when the access occurred, or where the data was taken from. Some coverage adds its own theories; this article treats only what the company confirmed as fact. Even if you received no notice, respond to any message that seems to know your booking with the steps above. The defense is the same whether or not you were affected.

Why correct booking details prove nothing

Checks that no longer work

  • The hotel, dates and price are right → probably real
  • They know my name and phone number → must be the property
  • They mention the exact room I booked → trustworthy

The check that still works

  • Only ask: does the request match the payment policy?
  • Check inside the official app you opened yourself
  • Card re-entry, payment via a link, off-policy transfers: refuse, however accurate the message is

When deciding whether a message from a booking site is real, most people unconsciously ask: does it know things only I and the site should know? The hotel, the dates, the price, how many guests. Until now that heuristic mostly held.

This time, what Booking.com acknowledged includes booking details and messages with properties. In other words, the very clues people rely on may now be in a third party's hands. Booking.com's own safety guidance explains that an attack compromising traveller data may be used for fraud such as phishing via WhatsApp, phone or email.

This site's view: judge by what's being asked, not where it came from

Common advice for spotting impersonation is "check the sender's address" or "messages inside the official app are safe". Both are useful signals, but neither is decisive. Booking.com's guidance itself says such messages most often claim to come from the accommodation, and sometimes even from Booking.com.

Stop judging by channel and judge by the request. Payment terms for a booked stay almost never change, and they are written in the booking confirmation. A rule of "if they ask for a payment the confirmation doesn't show, stop" works no matter how much the other side knows and no matter which channel it arrives through. It's the one line worth sharing with family and travel companions.

For an overseas breach this year that included government ID numbers, see the Odido data breach in the Netherlands; for a Japanese case where identity-document images leaked, see the Times Car breach. Connectivity risks while travelling are covered in the dangers of public Wi-Fi.

Sources (public record)

The facts in this article are based on the public information below. The number affected, timing and cause, which Booking.com has not disclosed, are not guessed at.

  • Booking.com, "Safety tips for travellers" (official safety guidance) — booking.com
  • BleepingComputer (April 13, 2026: reproduces the notice to guests and the spokesperson's statement) — bleepingcomputer.com
  • TechCrunch (April 13, 2026: spokesperson says it contained the issue, updated PINs and informed guests) — techcrunch.com
  • ABC News (April 13, 2026: data items listed in the notice, and the spokesperson's statement that financial information was not accessed) — abc.net.au

Update history

2026-09-30: First version, based on Booking.com's notice to guests and spokesperson statements (published in April 2026 coverage) and its official safety guidance. Will be updated if the scale or cause is disclosed.

FAQ

QWhat was exposed in the Booking.com breach?
A

According to the notice to guests, as published by news outlets, unauthorized third parties may have been able to access certain booking information: booking details, names, email addresses, phone numbers, addresses, and information guests shared with the property through the platform. A Booking.com spokesperson said financial information was not accessed. Outlets differ on how they describe the 'addresses' item, so check the wording of your own notice.

QHow many people were affected?
A

Booking.com has not disclosed how many guests were affected. It says it notified affected guests individually by email. It has also not said when or how the access happened.

QWhy was my reservation PIN reset?
A

Booking.com's notice says it updated the PIN of the affected reservations to keep them secure. You can see the new PIN by opening your booking in the official app or website. Booking.com says its customer service will only ever ask for your reservation ID and PIN, never your account password or card number.

QA property messaged me asking me to re-enter my card details. Is it real?
A

Booking.com says it will never ask you to share card details by email, phone, text or WhatsApp, and never ask for a bank transfer that differs from the payment policy in your booking confirmation. A correct hotel name and dates do not make a message genuine. Don't open the link; open your booking in the official app, check the payment policy, and if in doubt contact customer service from inside the app.

QI already entered my card details on a link. What now?
A

Booking.com's guidance: contact customer service immediately and report that you may have been scammed; reset your Booking.com password and turn on two-factor authentication; and contact your bank or card issuer to block the card, get a new one, and flag any charges you don't recognize.

QShould I change my Booking.com password?
A

Passwords are not listed in the notice. But if you reuse the same password elsewhere, this is a good moment to stop, and to turn on two-factor authentication on your Booking.com account.