Booking.com: Hackers accessed guest data in latest breach
Booking.com: Hackers accessed guest data in latest breach
A cyberattack exposed names, emails, and booking details for an undisclosed number of users; financial data was not accessed and PINs were reset.
The accommodation reservation site Booking.com has suffered a data breach, with unauthorized parties gaining access to guests’ booking information. The company said it noticed suspicious activity and promptly contained the issue, updating PIN numbers for affected reservations and informing its guests. It stressed that financial information was not accessed, and that the hackers may have been able to view details tied to a prior booking, including names, emails, addresses, phone numbers, and anything shared with the accommodation.
The breach marks the latest in a string of cybercrime attempts against the platform, which has faced rising scams such as fraudsters asking for payment details to pre-authorize trips. Booking.com acknowledged it has previously faced security incidents, notably a 2018 phishing incident in the United Arab Emirates that exposed the booking data of more than 4,000 people.
In its disclosure, the company noted it reported the breach to the Dutch privacy regulator 22 days after discovering it, which resulted in a €475,000 fine. It also highlighted ongoing industry calls to crack down on fake listings on booking sites. Booking.com is part of Booking Holdings, the U.S. company valued at around $137 billion.