Breach report
Travel & HospitalityBooking.com
Booking.com confirms hackers accessed customers' data
Booking.com confirmed in April 2026 that unauthorized parties had accessed some guests' reservation details, including names and contact information, amid reports that scammers were already using real booking data to target travelers.
Reported by TechCrunch
Records exposed
Undisclosed
Undisclosed
- When
- 2026
- How they got in
- Unauthorized access to reservation data (linked to phishing of hotel partners)
- Sector
- Travel & Hospitality
On April 13, 2026, online travel giant Booking.com confirmed that unauthorized third parties had been able to access some guests' booking information. The Amsterdam-based company said it noticed suspicious activity, took action to contain it, reset the reservation PIN numbers for affected bookings and informed the guests involved. It did not say how many customers were affected or when the activity began.
According to the company's notices, the exposed data included guests' names, email addresses, phone numbers, addresses, booking details and information that customers had shared with the properties where they were staying. Booking.com said financial information such as payment card details was not accessed and emphasized that it would never ask customers for sensitive information or bank transfers by phone, email or messaging apps.
Evidence suggested the data was being exploited before the official notice went out. TechCrunch reported that at least one affected traveler received a WhatsApp message containing accurate details of their reservation about two weeks before being told of the breach. That kind of message fits a long-running scam pattern in which criminals impersonate hotels, citing genuine booking information, and ask guests to confirm payment details or pay again through a fraudulent link. Security researchers, including a Microsoft report, have documented phishing campaigns against hotel staff using fake verification pages to plant remote access malware and hijack partner accounts on the platform.
Booking.com has been dealing with this fraud problem for several years. Consumer protection agencies in the United Kingdom and elsewhere have received hundreds of reports of hotel impersonation scams linked to the platform, with victims losing significant sums. The April 2026 incident increased pressure on the company to secure the accounts of its millions of accommodation partners, many of them small businesses with limited security resources, and to explain the scope of the latest intrusion.
The breach illustrates how travel platforms have become valuable targets not for payment data, which is heavily protected, but for itinerary and contact information that makes social engineering far more convincing. A message that correctly names a guest's hotel and dates is much harder to dismiss. For travelers, the practical advice is to verify any payment request through the official app and to be suspicious of urgent messages, even when they contain accurate booking details.