Booking.com has confirmed a data breach in which unauthorised parties accessed customers’ personal information, including names, contact details and reservation data. The company said it detected “suspicious activity” and acted to contain the issue, updating pin numbers for affected reservations and notifying guests.
The hacking attempted to exploit real booking data, with fraudsters potentially using the information to trick customers into making payments or sharing further details. The company declined to disclose how many individuals were affected but stated that financial information was not compromised.
This incident is the latest in a series of cybercrime attempts targeting the platform. In recent months, Booking.com has faced a rising number of scams where criminals request payment details for pre-authorisation before trips, then charge exorbitant amounts.
A similar breach occurred in 2018, when hackers stole login credentials from hotel employees in the United Arab Emirates, accessing booking data for over 4,000 people. Booking.com was fined €475,000 by the Dutch privacy regulator for reporting that breach 22 days late.



