Booking.com has confirmed a data breach in which unauthorised third parties gained access to customers’ booking information. The accommodation reservation platform said it noticed suspicious activity and took immediate action to contain the issue.
The company has updated the pin numbers for affected reservations and informed guests. An email to impacted customers stated that hackers may have accessed booking details, including names, emails, addresses, phone numbers and any information shared with the accommodation.
Booking.com declined to disclose how many people were affected, but stressed that financial information was not accessed. The platform lists more than 30 million properties worldwide and connects millions of travellers with experiences and accommodation.
This is the latest in a series of cybercrime attempts against the company. In 2018, criminals used phishing tactics to steal login details from hotel employees in the United Arab Emirates, gaining access to over 4,000 customer records. More recently, fraudsters have targeted users by asking for payment details to pre-authorise or verify trips before charging high amounts.
Booking.com reported the breach to the Dutch privacy regulator 22 days late, resulting in a €475,000 fine. The wider industry faces calls to crack down on fake listings on booking websites.
Booking.com is owned by Booking Holdings, a $137 billion US company that also owns OpenTable, Agoda and Kayak. The group employs more than 24,000 people worldwide.



