Apps & Consumer
Booking.com confirms data breach affecting customer information
Booking.com confirmed that hackers may have accessed customer personal data, though the company stated that financial information and physical addresses remain secure.
Booking.com confirmed on Monday that hackers may have accessed customers’ personal data, including names, email addresses, phone numbers, and booking details. The global travel and hotel reservation company notified customers of the security incident this past week, according to several online posts, after unauthorized third parties may have been able to access certain booking information. According to notifications received by users on Reddit, the compromised data may also include anything that customers shared with their accommodations. However, Booking.com told The Guardian that financial information was not accessed. The company also confirmed that physical addresses were not taken in the breach.
The exposure of this personal data has quickly translated into active security threats. Reports on Reddit, the platform where users posted breach notifications, indicate that some affected individuals received phishing messages—fraudulent communication used to steal data—via WhatsApp. One user told TechCrunch they received a WhatsApp message containing booking details and personal information, which suggests that hackers are leveraging the stolen information to target Booking.com customers. Booking.com spokesperson Courtney Camp told TechCrunch that the company “noticed some suspicious activity involving unauthorized third parties being able to access some of our guests’ booking information. Upon discovering the activity, we took action to contain the issue. We have updated the PIN number for these reservations and informed our guests.” Camp declined to answer specific questions regarding how many customers were affected or notified.
This incident follows previous security vulnerabilities associated with the platform’s broader network. In 2024, TechCrunch reported that hackers had infected several hotels’ computers with consumer-grade spyware, or stalkerware, specifically pcTattletale. In one of those previous cases, a victim was logged into their Booking.com administration portal when the stalkerware took a screenshot of their screen. The security of the platform’s reservation pipeline remains a critical concern given its massive scale; according to the company’s website, 6.8 billion customers have booked hotel rooms and homes since 2010.
Why it matters
The incident highlights the persistent vulnerability of travel platforms to social engineering, as attackers pivot from system-level compromises to direct customer phishing.