Booking.com customers have been continually reporting scams for the past five years, with fake emails and messages indicating that the threat actors have obtained travel destinations and other personal details provided by customers to the reservation agency.

The Attack Process

Affected customers report that they start suffering from phishing attacks soon after making a legitimate booking with the travel site, such as the one below:

 

The customer’s legitimate Booking.com reservation

A few months after the booking has been placed, customers report receiving emails claiming to come from Booking.com.

In the example shown below, the email supposedly came on behalf of the hotel, and has many of the expected signs of a phishing email, such as poor layout, spelling errors, and pressure to click on an unrelated link.

However, despite appearing flawed, the email does come with correct details such as the customer’s name, the hotel name, the dates of their stay, and even the confirmation number of the booking:

 

Booking.com Fake Hotel Message

Another example of phishing scams, sent to the same customer as above, also claimed to be from Booking.com and on behalf of the hotel. The “confirmation button”, if clicked, would redirect the victim to a URL generated by the Russian link shortening service nah.uy:

 

Booking.com Confirmation Scam Email

If the victim fell for this phishing scam, and clicked on the confirmation button, then they would be redirected to a near-perfect replica of the real Booking.com webpage.

This webpage also contains correct personal information regarding the customer’s stay, including the price of the booking.

The cybercriminals behind this attack use this fake webpage to encourage their victims to enter their payment card information. The cybercriminals could then either steal money from their account directly, or use the details in financial fraud.

 

The Phishing landing page & Social engineering through WhatsApp

As shown above, customers have also been subjected to social engineering attacks through messaging services such as WhatsApp, where cyber criminals pretend to be “Reservation Agents” or other trust-worthy positions within Booking.com’s organisation.

While phishing scams are nothing out of the ordinary, the personal data abused as part of these communications suggest that Booking.com’s systems have been breached, and that cybercriminals are able to extract reservation details, and use that data to harvest more valuable financial information from their customers directly.

The example shown here is not an isolated attack. Multiple reports have been made by numerous Booking.com customers over the past 5 years.

The overwhelming evidence from these reports suggests that Booking.com has been repeatedly compromised, has not informed their customers, and has not taken any effective measures to prevent reservation details from being stolen in the future.

When questioned about these attacks and data leaks, Booking.com has a standard response:

At Booking.com, security and the data protection of our customers and accommodation partners is a top priority.

We have been made aware that some accommodation partners have been targeted by phishing emails, which unfortunately has led to their systems becoming compromised. While the security breach was not on Booking.com, we know that the accounts of some of our accommodation partners have been affected. These accounts were quickly blocked by Booking.com to help reduce the risk and our teams are actively supporting these accommodation partners to ensure they can quickly and safely resume with their listings on our platform. We are also actively supporting any potentially impacted customers, as our security teams continue to investigate the issue.

 

A Compromised Supply Chain

Supply chain security is an integral part of any organisation’s cyber security posture.

Booking.com’s statement indicates that their customers are repeatedly suffering from the company’s “accommodation partners”, (e.g. hotels, private apartments, & hostels), being compromised by cyber attacks.

While Booking.com pass responsibility of the data breaches to their accommodation partners, their customers are still being affected, and are having their data leaked and exploited in repeated social engineering attacks.

This effectively means that Booking.com cannot guarantee the protection of their customers’ data, as they do not impose minimum cyber security and data storage requirements on their accommodation partners.

Booking.com may be able to protect their own systems and data, but if they continue to allow their supply chain partners to operate with substandard cyber security measures, they are allowing their customers to be exposed to cyber attacks, identity fraud, and even severe financial loss.

 

BBC WatchDog Investigation

We’re proud that this article led to an investigation being conducted by BBC WatchDog. This investigation resulted in a report on the One Show, which also featured an interview with our Managing Director, Morton Bell.

Watch the BBC’s report here:

https://www.youtube.com/watch?v=iOjy1SFkTlc

 

 

 
TecSec Services Ltd is an IT Support and Risk Management provider.
We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body.
We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.
For a free cyber security consultation and assessment for your organisation, contact us using the form below: