Hotel Phishing via WhatsApp: When the Booking Confirmation Becomes a Trap

Picture this: you have just booked a hotel in Barcelona, confirmation email received, trip sorted, looking forward to it. Then a WhatsApp message arrives with the right hotel name, the right dates and the right price. “Your payment could not be processed, please confirm your credit card details via the following link, otherwise your booking will be cancelled.” Would you click? Most people do, and that is exactly what makes this scam so effective.

In early June BACS warned about exactly this phishing wave running through booking platforms and WhatsApp. What the advisory does not spell out but provides the backdrop for: Booking.com disclosed a data leak in April 2026 in which booking data from millions of users was accessed by third parties. The current phishing campaign is a direct consequence.

How the attack works

What makes this scam so dangerous is that everything looks real, and not “real” in the sense of “passable knock-off” but genuinely real. Your hotel name, your travel dates, your booking price. The message reads like a standard platform communication and then comes the pressure: “Confirm now, or your booking gets cancelled.”

Nobody wants their holiday ruined over a payment glitch, and that is precisely what the attackers are counting on. The link leads to a page virtually indistinguishable from the genuine Booking.com site; credit card number, expiry date, security code, typed in, gone.

And it gets worse, because in some cases the attackers do not even bother with WhatsApp or email but write through the booking platforms own internal chat function. They have compromised the hotels account and message guests directly from inside the system, so from the victims perspective it looks like the hotel itself is writing. How would you tell the difference?

The Booking.com leak

In April 2026 Booking.com confirmed a security incident: names, email addresses, travel dates, hotel names and partial payment information had been accessed by third parties. The company stressed that no complete credit card data was affected, which is probably true but is cold comfort.

Because the attackers did not need credit card numbers, since that is what the phishing is for. What they needed was context, meaning real bookings with real details to craft believable messages, and that is exactly what the leak delivered. Security researchers have been tracking the campaign since March 2026 by the way, before Booking.com even publicly confirmed the leak; the data was apparently circulating weeks before the official disclosure…

Why this hits businesses too

Two words: business travel. Any company whose staff book through Booking.com, Expedia or similar platforms (and in Switzerland that is a lot of them) is a potential target. The phishing messages land on work email addresses and company phones, and when an employee enters the corporate credit card through one of these links it is not their personal account at risk but the companys.

But there is also the hotel side of this, because Swiss hotels using Booking.com as a sales channel need to understand that their platform accounts are targets for account takeover. A compromised hotel account gets used to phish guests directly through the platform, and who takes the reputational hit? The hotel, not Booking.com.

What to do about it

If you are a traveller: any message asking you to re-enter payment details via a link is suspicious. No legitimate booking platform requests this via WhatsApp, email or chat. When in doubt log in directly through the official website or app, never through a link someone sent you, and check whether there is actually a problem.

If you run a business: a quick heads-up in the next team meeting or via Slack does the job. “Anyone who has booked through Booking.com and receives a payment confirmation message: do not respond, check directly through the official site.” Three sentences that can prevent real damage.

If you are a hotel: two-factor authentication on your platform accounts, right now. And check regularly whether messages have been sent from your account that you did not write.

The bigger picture

This case shows a pattern we keep running into in our work: a data leak at a third-party provider hands attackers the context for highly personalised phishing. The actual attack comes weeks later and does not hit the platform operator but the end users, meaning you, your employees, your customers. The weakest link in the chain is often a service you did not even have on your risk radar…

Our security assessments cover third-party risks too: which platforms do your people use, what data sits there, and what happens when one of those services gets compromised? If you want answers: get in touch.

Sources: BACS Weekly Review KW 22, BleepingComputer: Booking.com Data Breach