Booking.com confirmed an incident. Attackers may have accessed reservation data
The combination of contact details and specifics about a particular reservation gives attackers very strong material for targeted phishing. If someone knows where you'll be staying, when you are traveling and under what name the reservation is booked, they can craft a far more convincing scam than ordinary spam.

What Booking.com confirmed
According to the company's statement, Booking.com detected 'suspicious activity' during which unauthorized third parties may have accessed some guest booking information. The firm said that after discovering the incident it began addressing the situation, changed the PINs of the affected reservations and informed customers directly by email. So far, however, it has not specified how the intrusion occurred or how many users were affected.
Media reports based on the notice sent to customers state that among the potentially exposed data might have been name, email address, phone number, postal address, reservation details and also communications that the user shared with the accommodation. Booking.com also told the media that financial data should not have been accessible.
The biggest risk now may not be the leak itself, but what follows it
The combination of contact details and specifics about a particular reservation gives attackers very strong material for targeted phishing. If someone knows where you'll be staying, when you are traveling and under what name the reservation is booked, they can craft a far more convincing scam than ordinary spam.
That's the most important aspect of the whole event. The incident itself is unpleasant, but its second phase could have an even greater impact: fake emails, WhatsApp messages or phone calls impersonating Booking.com or the hotel itself. The company explicitly warns customers about this in its notice. According to available information, there have also been cases of phishing messages containing personal and booking details, but it's not confirmed that these are directly related to this incident.
The PIN was changed, questions remain
According to available information, Booking.com changed the PINs on affected reservations, and some reports even mention past reservations. That's a logical step, because the combination of a reservation number and PIN can in some situations allow access to details of a stay. However, the company has still not answered several crucial questions: how many accounts or reservations were affected, whether it was a compromise of internal systems, partners or another vector, and how long attackers had access to the data.
The lack of these details is so far the biggest weakness in the public communication around the incident. There is confirmation and a defensive step, but the technical picture of the attack is still missing.
Booking.com has faced travel data misuse before
The new incident follows earlier security issues around the platform. Evropský sbor pro ochranu osobních údajů recalls the 2018 case when attackers, during a phone scam targeting hotels in Spojených arabských emirátech, gained access to the data of 4 109 Booking.com customers. The attack then targeted hotel staff, not Booking.com's infrastructure directly.
It also fits into a broader context where Booking.com and security firms already warned in 2024 about a sharp rise in travel-related scams. In public statements, increases of 500 to 900 % over the previous 18 months were cited, with tools like generative AI playing a significant role by making it easier for attackers to create convincing phishing messages.
What users should do
If you received a notice about the incident from Booking.com, you should assume that your data could be used in follow-up fraud. Caution is also advisable for other users of the service, because attackers may take advantage of the media attention and send fake warnings even to people not directly affected by the incident.
Particularly suspicious are messages that create pressure to act quickly, demand payment of a balance, ask you to confirm your card or click a link to 'verify' your stay. The safer route is always to open Booking.com manually, sign in the usual way, and verify everything directly in your account or via official support. Booking.com also reminds in its notices that users should not share sensitive payment details by phone, email, SMS or via WhatsApp.
For now, the incident is mainly a warning
On today's internet, it's long no longer true that the biggest problem is just the data leak itself. Often it's more of a springboard for further attacks. And especially in the travel sector, where people routinely communicate with hotels, handle payments, change reservations and stress before departure, such phishing works exceptionally well.
In the case of Booking.com, it's therefore important to separate two things. The incident and the change of reservation PINs are confirmed. What remains unconfirmed is the scope of the impact and the technical nature of the attack. But one thing is already important for users: any unexpected message about a reservation, payment, or verification now deserves maximum caution.