Skip to content
>_ITDITDWeb Security Platform
tag

travel

2 articles with this tag

2026-09-30

Correct booking details don't prove a message is real — the Booking.com reservation data access and how to spot fake property messages

In April 2026 Booking.com notified guests that unauthorized third parties may have been able to access certain booking information, updated the PINs of the affected reservations, and said it had contained the issue. According to the notice and the company's spokesperson as reported, the information included booking details, names, email addresses, phone numbers and messages shared with properties; financial information was not accessed. The number affected and the cause were not disclosed. This site's take: what broke here is the habit of trusting anyone who knows the details of your booking. A correct hotel name, date and price no longer prove anything. The only test that still works is whether a request matches the payment policy in the booking you open yourself in the official app. A request to re-enter card details, pay through a link, or make a transfer not in the policy is where you stop.

2026-09-30

What leaked is when you travel and on which train — the Trenitalia data breach and how to spot fake delay-refund messages

Italian rail operator Trenitalia sent customers a notice under Article 34 of the GDPR saying a cybersecurity incident caused by unidentified external parties led to unauthorised access to some personal data linked to travel tickets (titoli di viaggio). Follow-up notices for jointly controlled tickets describe it as the same event Trenitalia communicated on June 26, 2026. The data may include name, date and place of birth, email and phone number, itinerary details such as route, date, time and ticket number, loyalty card code, employer, and identity document details; the notice for UnicoCampania regional tickets also lists the Italian tax code (codice fiscale) and gender. Trenitalia says account login data, passwords and payment information were not involved. It notified the Italian data protection authority (Garante) and CSIRT Italia and filed a criminal complaint with the Rome prosecutor. This site's take: what leaked is an itinerary — when, where and on which train — and that is exactly what makes a fake 'your train was delayed, claim your refund' message convincing. Real delay compensation is either requested by you through Trenitalia's own channels or, for regional digital tickets, paid automatically to the card you bought with. No genuine refund asks you to type your card number into a link from a text message.