VERDICT: STRONGLY VERIFIED (V4)
A scam message can know where you are staying, when you are travelling and which property you booked.
CLAIM
Reservation-hijack scams use genuine booking context to send travellers convincing payment or card-verification requests through channels they already associate with their trip.
EVIDENCE
Gen Threat Labs reported in May 2026 that it had identified more than 350 accommodation-specific reservation-hijack scam flows across 50 countries. Its dataset included 31 compromised accommodations linked to the United Kingdom. Researchers analysed fraudulent landing pages, URLs, messages and in-app evidence and said victims had received reservation-specific information before being pushed to pages customised around the accommodation.
Gen uses “compromised accommodation” carefully: it means reservation context associated with that accommodation was compromised and used in an intercepted attack flow. The source of the compromise could vary, including accommodation accounts, partner accounts, email, property-management systems or third-party services.
TEST
This evidence establishes the attack model and UK presence, but it does not prove that Booking.com itself was the source of every data compromise or that all attacks used the same malware chain. TVD therefore does not make either claim.
VERDICT
V4 — Strongly Verified. The mechanism is strongly supported by detailed threat research with UK cases in the dataset; attribution of individual compromise points varies.
How to prevent it
- Do not treat correct booking information as proof that a payment request is genuine.
- If asked to re-enter card details or make an unexpected payment, open the booking service independently rather than following the supplied link.
- Contact the accommodation using independently verified details if anything has changed.
- If you entered card details into a suspicious page, contact your card issuer promptly.
Warning signs
- A message knows genuine booking details but unexpectedly asks you to re-enter payment information.
- You are told the reservation will be cancelled unless you make another payment or verification payment.
- The link opens a payment page outside the route you normally use to manage the booking.
What to do if you responded
Contact your payment provider promptly if you entered payment details or made a payment. Open the booking platform independently, check the reservation and contact the accommodation through independently verified details. Preserve the message and URL.
Where to report it
Report the message to the booking platform or accommodation through its genuine channels and report financial loss through the appropriate official fraud-reporting route. See Fraud First Aid.
Source: Gen Threat Labs, “When Hotel Scams Know Your Booking”, 28 May 2026, plus its March 2026 Reservation Hijack investigation.
Evidence boundary: TVD does not attribute all reservation-hijack attacks to any single booking platform, accommodation provider or software company.