Hotel reservations platform Booking.com has confirmed that unauthorized parties have accessed its customer booking data, in another incident that highlights how closely customer experience is tied to cybersecurity resilience.
In a notice sent to affected users, the Amsterdam-headquartered company wrote:
“[W]e’re writing to inform you that unauthorized third parties may have been able to access certain booking information associated with your reservation.”
Booking.com has begun emailing affected users in Australia and Ireland about “suspicious activity” linked to certain bookings.
The company said it detected suspicious activity affecting a number of reservations and took steps to contain the issue. While financial data was not accessed, exposed information may include personal and booking-related details.
How the Booking.com Breach Began Outside the Customer Interface
There are indications that the incident may have originated from a broader phishing campaign targeting hotel partners.
Security researchers have linked the breach to attacks where hospitality staff are tricked into executing malicious actions via spoofed communications. Once compromised, attackers can access legitimate reservation data and use it to target customers with highly convincing follow-on scams.
Cybersecurity service provider Bridewell has observed a campaign of malicious activity targeting the hotel and retail sector. Joshua Penny, Senior Threat Intelligence Analyst at Bridewell, wrote in a blog post:
“The primary motivation driving this incident is financial fraud, targeting two victims: hotel businesses and hotel customers, in sequential order. The threat actor(s) utilize impersonation of the Booking.com platform through two distinct phishing kits dedicated to harvesting credentials and banking information from each victim respectively.”
The three-stage infection chain sends targeted emails to the Booking.com partner hotel, harvesting credentials and targeting service desk agents using a partner phishing kit, then using a customer phishing kit to target the hotel customer's financial data.
Cofense Intelligence has also been tracking a series of Booking.com spoofing emails targeting hotel chains since late 2024. The phishing campaigns deliver remote access trojans (RATs) or information stealers via a link embedded in the emails to a fake CAPTCHA site. The website delivers a malicious script instead of a verification code and prompts the user to run the script using Windows keyboard shortcuts. According to the Cofense blog:
“These fake CAPTCHAs used for malware delivery are known as ClickFix attacks, and they are notable for having variants that convincingly spoof various brands such as Booking.com and Cloudflare while delivering arbitrary malicious script payloads.”
This highlights the reality that customer experience can be disrupted even when the core platform is not compromised.
The incident indicates how customer trust now spans an entire network of partners. Booking platforms operate as ecosystems connecting travelers and accommodation providers. Weaknesses at the partner level, such as compromised hotel accounts, can expose customer data indirectly.
Customers, however, still associate the experience with one brand. Accountability is shared, but perception is not.
CX leaders need to be aware that personalization strategies prioritizing tailored, contextual communication involve customer data that can be weaponized.




