Cybercriminals stole booking data from at least 350 hotels, vacation rentals, motels, and guesthouses across 50 countries and used the information to launch targeted phishing scams designed to steal travelers’ credit card details. The stolen reservation information—including guest names, specific check-in and check-out dates, and prices—was used to create fraudulent messages that closely mimic legitimate communications from booking platforms or accommodations.

Security company Norton identified phishing websites that replicated hotel branding and included victim-specific reservation details. In one observed case, a phishing message sent via WhatsApp impersonated Booking.com, listed exact stay dates, and prompted the recipient to click a link to “confirm” their booking. The link led to a fake site featuring a chatbot that collected credit card information and sent it directly to hackers.

Germany had the highest number of potentially affected accommodations, followed by France, the U.K., Italy, Spain, and the U.S. Most of the targeted properties are small- or medium-sized establishments. Luis Corrons, research lead at Gen Digital, said criminals are “weaponizing real reservation context to push travelers into fake verification or payment flows.” He added that the inclusion of accurate details makes it harder for recipients to distinguish scams from genuine messages.

Corrons noted that not every phishing message stemmed from a direct breach of a hotel’s internal systems. Hackers may have obtained booking data through compromised third-party services, malware-laced emails sent to hotel staff, or unrelated data breaches. In one incident analyzed by cybersecurity firm Sophos, an attacker posed as a guest who had lost a passport, then sent a follow-up message containing a malware-laced file that ultimately enabled fraudulent messages to be sent from the hotel’s Booking.com account.

Don Smith, vice president of threat research at Sophos, said threat actors “love context because it makes phishing lures more compelling.” He explained that travelers are especially vulnerable during stressful moments, making them more likely to click on deceptive links. Corrons advised travelers to verify suspicious messages by contacting the hotel through a known, trusted channel. “Even if the data in a message is real, it does not mean the message itself can be trusted,” he said.

Booking.com stated it continues to strengthen its defenses to limit opportunities for bad actors. Cloudbeds, a hotel management platform, said it has not been breached and attributed the attacks to credential-phishing campaigns. Aaron Ownbey, vice president of engineering at Cloudbeds, emphasized the need for better staff training, phishing-resistant authentication, and tighter controls on guest data access across the hospitality industry.