Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Booking.com confirms breach of customer data

Booking.com said that unauthorized third parties may have accessed some customers’ names, email addresses, phone numbers, physical addresses, booking details, and messages shared with accommodations.

The travel platform said it recently alerted affected guests, contained the incident, and reset PINs tied to the reservations.

Booking.com did not say how many customers were affected.

One customer said they received a WhatsApp phishing message two weeks earlier that included booking details and personal information.

Booking.com told The Guardian that no financial information was accessed.

🔗 Source: TechCrunch

🧠 Food for thought

Implications, context, and why it matters.

This breach may start with compromised accommodation partners rather than Booking.com’s core systems

  • Some cases begin when criminals break into hotels or other accommodation partners, instead of hacking Booking.com’s central systems 1.
  • Fraudsters run phishing campaigns that mimic reservation cancellations, then plant remote access malware (malicious software that lets outsiders control a computer) on hotel computers 2.
  • After they enter a hotel network, criminals can take over its legitimate Booking.com account, pull guest details, and send fake payment requests through the platform’s official messaging system 1.
  • The threat is large. Booking.com’s chief information security officer (CISO) said the company blocked 50 million phishing attempts through its internal messaging systems in one recent month 3.

Platform trust takes the hit, with lessons for online marketplaces

  • When attackers send messages from real partner accounts, the platform’s trust model fails. Even careful travelers who sign in directly can still receive scams in an official inbox 1.
  • This risk goes beyond travel. It stems from a supply-chain vulnerability (risk introduced through third-party partners or vendors) where a hotel or other accommodation partner breach can spread harm across the wider marketplace 3.
  • The incident could push platforms to require tougher security rules for accommodation partners, even if that creates business friction 4.
  • Booking.com has shared few details about the breach’s scale, which may draw regulators’ attention. A past case led to a 475,000 euros (US$556,000) General Data Protection Regulation (GDPR) fine after a 22-day reporting delay 5.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.