Skip to main content
Breach Signal

Breach report

Travel & Hospitality

Booking.com

Booking.com confirms hackers accessed customers' data

Booking.com confirmed in April 2026 that unauthorized parties had accessed some guests' reservation details, including names and contact information, amid reports that scammers were already using real booking data to target travelers.

Reported by TechCrunch

Records exposed

Undisclosed

Undisclosed

When
2026
How they got in
Unauthorized access to reservation data (linked to phishing of hotel partners)
Sector
Travel & Hospitality

On April 13, 2026, online travel giant Booking.com confirmed that unauthorized third parties had been able to access some guests' booking information. The Amsterdam-based company said it noticed suspicious activity, took action to contain it, reset the reservation PIN numbers for affected bookings and informed the guests involved. It did not say how many customers were affected or when the activity began.

According to the company's notices, the exposed data included guests' names, email addresses, phone numbers, addresses, booking details and information that customers had shared with the properties where they were staying. Booking.com said financial information such as payment card details was not accessed and emphasized that it would never ask customers for sensitive information or bank transfers by phone, email or messaging apps.

Evidence suggested the data was being exploited before the official notice went out. TechCrunch reported that at least one affected traveler received a WhatsApp message containing accurate details of their reservation about two weeks before being told of the breach. That kind of message fits a long-running scam pattern in which criminals impersonate hotels, citing genuine booking information, and ask guests to confirm payment details or pay again through a fraudulent link. Security researchers, including a Microsoft report, have documented phishing campaigns against hotel staff using fake verification pages to plant remote access malware and hijack partner accounts on the platform.

Booking.com has been dealing with this fraud problem for several years. Consumer protection agencies in the United Kingdom and elsewhere have received hundreds of reports of hotel impersonation scams linked to the platform, with victims losing significant sums. The April 2026 incident increased pressure on the company to secure the accounts of its millions of accommodation partners, many of them small businesses with limited security resources, and to explain the scope of the latest intrusion.

The breach illustrates how travel platforms have become valuable targets not for payment data, which is heavily protected, but for itinerary and contact information that makes social engineering far more convincing. A message that correctly names a guest's hotel and dates is much harder to dismiss. For travelers, the practical advice is to verify any payment request through the official app and to be suspicious of urgent messages, even when they contain accurate booking details.

More from the wire

More in Travel & Hospitality.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.