All guides
Booking5 min read8 September 2026

The Booking.com WhatsApp Scam Hit Me Twice. Here's How It Works

Real booking details are conning holidaymakers out of thousands. Booking.com called it "internal" and blamed the hotel.

'They knew our booking PIN': inside the WhatsApp scam stalking Booking.com's guests - and the runaround I got when I complained

By Max Letek, Lost Land Travels | Monday 7 September 2026

In March, I was a good week into a trip to Mexico, heading off to new location in Tulum booked through Booking.com, when a WhatsApp message landed that stopped me cold. It had our names, our check-in and check-out dates, and our booking PIN. It said the hotel needed us to pay an "additional resort charge" through a link, or the reservation would be cancelled.

It looked, in every respect, like it had come from the property. When I called the front desk to check, the staff didn't seem surprised. They told me this "was an issue with Booking.com" - that the platform had "been hacked" and there was nothing they could do about it.

I didn't pay. I've spent fifteen years in digital marketing and SEO, much of it picking apart phishing pages for a living, and something about the link felt wrong. But I could see exactly why someone would pay. The message wasn't a clumsy, misspelled scam email. It had our actual booking data in it - information that, as far as I knew, only Booking.com and the hotel had.

I assumed it was a one-off. I was wrong.

It happened again - and this time I have the receipts

On 5 September, ahead of a booking at the Elba Sunset Mallorca Thalasso Spa for 23–28 September, a WhatsApp message arrived from a business account calling itself "Assine SKY", with a phone number registered in Brazil. It addressed me by my full name and knew my exact reservation dates. The sender claimed to be "Diana", a "check-in manager" at the hotel, and demanded I complete a "mandatory verification of guest details" by clicking a link - to "verify my bank card". If I didn't comply within 12 hours, it said, the booking would be automatically cancelled and I'd be charged a fee.

The only thing that stopped me a second time was the foreign number and the fact I'd seen this exact playbook before. Someone who hadn't would have had every reason to believe it: a named contact, a real hotel, real dates, a countdown clock, and a threat calibrated to make you act before you think.

I contacted the hotel. They blamed Booking.com. This was, word for word, the same response I'd had in Mexico six months earlier.

So this time, I complained to Booking.com directly - and kept the transcript.

"It's totally an internal thing between us and the property"

I opened a chat with Booking.com's support team on the morning of 7 September and laid out the full history: two phishing incidents in six months, both using data no one but Booking.com and its partner hotels should have had, and a formal written complaint asking three questions - how bad actors are getting this data, what compensation I'm entitled to under GDPR, and what's being done to stop it happening a third time.

The first agent, Joshua, was sympathetic in the way a script is sympathetic. "I completely understand how unsettling and frustrating this situation must feel for you, especially since it's the second time your personal booking details have been compromised," he wrote, before telling me my case had been "submitted to our Fraud Ops team" and was being "treated as a priority." He asked me to "keep your lines open and active" so I wouldn't miss an update. Eleven minutes later, having heard nothing further, he sent a closing message and ended the chat "due to inactivity" - before I had a chance to reply. No reference number. No case ID. Nothing to follow up on.

I opened a second chat and asked the new agent, Belal, for a complaint reference number. What followed is worth setting out close to verbatim, because it's more revealing than anything a press office would ever put in a statement.

Belal confirmed my case had been raised: "I can confirm that is something related to the property website and we already report this to our security team and they will make sure to investigate this with the property." When I asked for a reference number to track it, he told me there wasn't one: "It's totally an internal thing between us and the property and our security team... your reference will be your booking number as it's an internal thing."

I pointed out that this wasn't what Booking.com's own published complaints procedure promises. I quoted it back to him: "We'll confirm receipt of your complaint via the Extranet inbox or by email, and provide you with more info about the process and what you can expect for the next steps." Belal didn't dispute that this was the policy. He simply repeated that there was no other way to complain "in our system," and - when I asked directly whether I'd get compensation - offered this instead: "if you asked for a compensation maybe you can ask the property if they agreed to refund you something we don't have any problem from our end."

Booking.com's own agent, in other words, redirected a complaint about Booking.com's own data ending up in a criminal's hands to a request for a discretionary goodwill gesture from the hotel. When I said plainly that the data had been breached from Booking.com's ecosystem and that this was Booking.com's responsibility under GDPR, Belal's reply was: "I understand but your date is in the property website also and they already informed you via chat that is a scam. And we already reported this issue." That was the full extent of the accountability on offer: an acknowledgment that yes, it's a scam, and a note that it had been passed along internally, with no way for me to verify that, track it, or ever hear the outcome. I told Belal, truthfully, that I was writing about this exchange. It didn't change the answer.

I closed the chat with no complaint reference, no case number, no promised timeline, and no indication that "our security team" and "the property" would ever tell either of us what actually happened.

A scam with a name

What happened to me has a name in the cybersecurity world: "I Paid Twice", a campaign identified by researchers at the threat intelligence firm Sekoia, and tracked separately by Microsoft under the identifier Storm-1865. It has been running since at least early 2023, and by the researchers' own account it has only accelerated since.

The mechanism is not a breach of Booking.com's own servers in the way most people imagine a "hack". Instead, it exploits the weakest link in a vast, decentralised network: individual hotel staff. According to Sekoia's analysis, criminals send spear-phishing emails to hotel employees - often spoofed to look like they come from Booking.com itself, referencing a "new booking" or a guest complaint. Clicking through leads to a fake CAPTCHA page and, via a technique called "ClickFix", tricks the employee into copying a command into their computer that silently installs remote-access malware - researchers have identified strains including PureRAT, XWorm, VenomRAT, AsyncRAT and NetSupport RAT.

Once inside, criminals don't need to touch Booking.com's core infrastructure at all. They simply log into the hotel's own Booking.com extranet account - the portal partner properties use to manage reservations and message guests - using the hotel's own stolen credentials. From there, they can see every live booking: names, dates, phone numbers, confirmation codes. Researchers say access to compromised hotel accounts is bought and sold on Russian-language cybercrime forums for anywhere between $30 and $5,000 each, with some criminal groups claiming to have made more than $20m from the scheme.

Armed with that data, the final step is almost quaint by comparison: a WhatsApp or SMS message to the guest, using real details to establish trust, followed by a link to a fake payment page designed to harvest card numbers under the guise of a "deposit", "resort fee" or "verification" - exactly the shape of both messages I received.

Not a niche problem

Booking.com has repeatedly characterised these incidents as rare. Its own agent, in my case, called it "something related to the property website" - a framing that keeps the fault at arm's length. The evidence gathered by consumer groups, regulators and security researchers tells a broader story.

The consumer champion Which? says it now receives more fraud complaints about Booking.com than about any other accommodation site, and in a survey of its members found that roughly one in ten customers who had booked through the platform in the previous two years reported receiving a suspected scam message. In the UK, Action Fraud logged 532 reports linked to Booking.com scams between June 2023 and September 2024 alone, with losses totalling around £370,000.

Then, in April this year, Booking.com wrote to customers warning that unauthorised parties had accessed reservation data - names, contact details, addresses and booking specifics - through compromised hotel partner accounts. More than 4,000 travellers are reported to have had their details exposed in that incident, with roughly 300 cases going on to involve stolen payment card data. Spain's national cybersecurity institute, INCIBE, and the Guardia Civil felt the problem serious enough to renew a public fraud warning in mid-August - weeks before the "Diana" message reached me about my Mallorca booking.

Booking.com has not published a full account of how many guests have ultimately been affected, either by the April incident or by the wider "I Paid Twice" campaign. When approached by researchers and journalists, the company's position has been that it is seeing "an increasing number of online scams targeting many businesses in the e-commerce space," that such incidents are rare relative to its overall booking volume, and that it "would never ask for sensitive information or bank transfers" over chat, WhatsApp, email or phone.

That last point is true, and it's the single most useful fact in this entire story. It is also, notably, not the same as saying the underlying problem has been fixed - or that a customer reporting it twice can expect a straight answer.

Booking.com has been here before

What makes this hardest to write off as an unfortunate one-off is that it isn't the first time. In December 2018, hotel staff in the United Arab Emirates were tricked in an almost identical way, handing over their extranet login details to fraudsters, who went on to access more than 4,000 guest records and expose around 300 sets of card details to follow-up phishing.

Booking.com didn't notify the Dutch data protection authority, its lead EU regulator, until 7 February 2019 - the regulator found the company had known enough to trigger the mandatory 72-hour GDPR reporting window by 13 January, meaning it should have reported by 16 January. The delay, which the regulator called a "serious violation," resulted in a €475,000 fine in 2021.

Set the two incidents side by side and the similarity is uncomfortable: hotel staff phished, extranet credentials stolen, guest data harvested, follow-on phishing of the guests themselves - in 2018, and again in 2026. Compliance analysts have pointed out that mandatory multi-factor authentication for hotel partner accounts still does not appear to be enforced across the platform, eight years after the vulnerability was first exploited at scale and five years after the company was fined for mishandling the fallout.

Why hasn't this been fixed?

Part of the answer is structural. Booking.com's business model depends on connecting travellers to more than a million individual, independently run properties - from international chains down to family-run guesthouses with no IT department at all. Enforcing strong security standards, like mandatory hardware or app-based two-factor authentication, on every one of those partners is a genuine operational challenge, and one that creates friction for the very partners the platform relies on.

But that explains the vulnerability. It doesn't explain the customer service culture around it. What I ran into wasn't just a security gap - it was a front line trained to sound sorry without ever writing anything down. No case number. No committed timeline. No email confirmation, despite the company's own published promise of one. A suggestion, when pressed on compensation, to go and ask the hotel for a favour. Which? has separately called for regulatory scrutiny of Booking.com - including possible investigation by Ofcom under the Online Safety Act - and has urged the company to introduce identity verification for hosts, remove flagged fraudulent listings within 24 hours, make scam reporting easier to find, and provide dedicated support for fraud victims rather than routing them through general customer service that, in my experience, has no authority to log a formal complaint at all.

It's also worth naming the incentive problem plainly: every time this is framed as "something related to the property website" rather than a Booking.com security failure, the company's own liability looks smaller. My hotel in Mexico telling me "Booking.com was hacked", and my hotel in Mallorca doing the same, wasn't necessarily false - but it was also, conveniently, not "we let a criminal into our own extranet account." Both framings can be technically defensible and still leave the guest exactly as exposed, with no one accountable for the actual harm.

What to do if it happens to you

Based on my own experience and guidance from Booking.com itself, Which?, and fraud-recovery resources:

  • Do not click the link or pay. Booking.com has confirmed it will never ask for payment, card details or "verification" via WhatsApp, SMS, email or phone call - even if the message appears inside Booking.com's own official messaging system, and even if it names a real member of hotel staff.

  • Verify independently. Call the hotel using the phone number on its official website or Google listing - never a number given in the suspicious message - or check your booking directly through the Booking.com app.

  • Insist on a written complaint reference. Booking.com's own complaints policy promises confirmation "via the Extranet inbox or by email" with a defined process and regular updates. If a support agent tells you the matter is "internal" and there's no reference number, ask them to point you to where that policy is published and push back - in writing, not chat.

  • If you've already entered card details, call your bank or card provider immediately to block the card and dispute the transaction, then report the fraud to Action Fraud (in the UK), the FTC's ReportFraud.ftc.gov (in the US), or your national equivalent.

  • Watch your accounts afterwards. Consider a fraud alert with your credit reference agency and keep an eye on statements for weeks, not days - the data harvested in these campaigns tends to circulate on criminal forums well after the initial message.

I got lucky twice. The next person to receive one of these messages - with their name, their dates and their booking reference sitting right there in black and white - may not stop to question it. And if they complain afterwards, on this evidence, they should not expect a reference number.


Max Letek is a marketing consultant and writer at Lost Land Travels.


Some links on Lostland are affiliate links. If you book through them we may earn a small commission at no extra cost to you. See our affiliate disclosure.

Keep reading