• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Booking.com Confirms Customer Breach After ClickFix Campaign Hit Hotel Partner Network

  • SOFX Staff Writer
  • April 14, 2026
(Casimiro PT / Shutterstock.com)
Share on FacebookShare on TwitterLinkedIn

Booking.com confirmed this week that unauthorized third parties accessed customer booking data, including names, email addresses, and phone numbers. The company said it updated reservation PIN numbers on affected accounts and notified guests. It declined to say how many customers were impacted.

“We noticed some suspicious activity involving unauthorized third parties being able to access some of our guests’ booking information,” spokesperson Courtney Camp said. “Upon discovering the activity, we took action to contain the issue.”

A separate spokesperson said the problem “has been fully contained.” Financial data and physical addresses were not accessed, the company later confirmed.

The timing fits a documented pattern. Analysts at Cofense had been tracking a ClickFix campaign, a social engineering technique that tricks hotel staff into executing malware through fake CAPTCHA verification pages, targeting Booking.com hotel partners with spoofed emails since November 2024.

Some 47% of total campaign activity was concentrated in March 2025 alone, according to Cofense. The attacks delivered remote access trojans and information stealers to hotel staff machines, giving attackers access to real guest reservation data.

Researchers at Bridewell separately documented a three-stage infection chain as recently as February 2026 in which compromised hotel partner credentials were used to target customers directly via WhatsApp, pairing fraudulent payment requests with legitimate booking details to appear credible.

At least one affected customer reported receiving a WhatsApp phishing message two weeks before this week’s notification that included accurate booking details, consistent with the downstream fraud model both firms described.

Booking.com was previously fined €475,000 by the Dutch Data Protection Authority following a 2018 breach in which phishing attacks on hotel employees in the United Arab Emirates exposed data on more than 4,000 customers.

That fine was issued for notifying the regulator 22 days past the legal deadline. The company lists more than 30 million properties globally and reports 6.8 billion bookings since 2010.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

by SOFX Staff Writer
July 18, 2026
2

The average Russian recruit survives just 20 to 30 minutes at the front in Ukraine before being killed or wounded,...

Hegseth Orders Testosterone Screening for U.S. Troops

Hegseth Orders Testosterone Screening for U.S. Troops

by SOFX Staff Writer
July 16, 2026
6

War Secretary Pete Hegseth announced Wednesday that the U.S. military will begin annually screening service members aged 30 and older...

Iran Tracked US Troops Using Cellular Flaws and Ad Brokers

Iran Tracked US Troops Using Cellular Flaws and Ad Brokers

by SOFX Staff Writer
July 16, 2026
0

Iran ran a dual-track surveillance operation against U.S. military personnel in the Middle East before and during its retaliatory strikes...

ADVERTISEMENT
ADVERTISEMENT
Home Global Operations

Booking.com Confirms Customer Breach After ClickFix Campaign Hit Hotel Partner Network

  • SOFX Staff Writer
  • April 14, 2026
(Casimiro PT / Shutterstock.com)
Share on FacebookShare on TwitterLinkedIn

Booking.com confirmed this week that unauthorized third parties accessed customer booking data, including names, email addresses, and phone numbers. The company said it updated reservation PIN numbers on affected accounts and notified guests. It declined to say how many customers were impacted.

“We noticed some suspicious activity involving unauthorized third parties being able to access some of our guests’ booking information,” spokesperson Courtney Camp said. “Upon discovering the activity, we took action to contain the issue.”

A separate spokesperson said the problem “has been fully contained.” Financial data and physical addresses were not accessed, the company later confirmed.

The timing fits a documented pattern. Analysts at Cofense had been tracking a ClickFix campaign, a social engineering technique that tricks hotel staff into executing malware through fake CAPTCHA verification pages, targeting Booking.com hotel partners with spoofed emails since November 2024.

Some 47% of total campaign activity was concentrated in March 2025 alone, according to Cofense. The attacks delivered remote access trojans and information stealers to hotel staff machines, giving attackers access to real guest reservation data.

Researchers at Bridewell separately documented a three-stage infection chain as recently as February 2026 in which compromised hotel partner credentials were used to target customers directly via WhatsApp, pairing fraudulent payment requests with legitimate booking details to appear credible.

At least one affected customer reported receiving a WhatsApp phishing message two weeks before this week’s notification that included accurate booking details, consistent with the downstream fraud model both firms described.

Booking.com was previously fined €475,000 by the Dutch Data Protection Authority following a 2018 breach in which phishing attacks on hotel employees in the United Arab Emirates exposed data on more than 4,000 customers.

That fine was issued for notifying the regulator 22 days past the legal deadline. The company lists more than 30 million properties globally and reports 6.8 billion bookings since 2010.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

by SOFX Staff Writer
July 18, 2026
2

The average Russian recruit survives just 20 to 30 minutes at the front in Ukraine before being killed or wounded,...

Hegseth Orders Testosterone Screening for U.S. Troops

Hegseth Orders Testosterone Screening for U.S. Troops

by SOFX Staff Writer
July 16, 2026
6

War Secretary Pete Hegseth announced Wednesday that the U.S. military will begin annually screening service members aged 30 and older...

Iran Tracked US Troops Using Cellular Flaws and Ad Brokers

Iran Tracked US Troops Using Cellular Flaws and Ad Brokers

by SOFX Staff Writer
July 16, 2026
0

Iran ran a dual-track surveillance operation against U.S. military personnel in the Middle East before and during its retaliatory strikes...

Ukrainian Sniper Group Claims 1,700-Meter Kill of Russian Soldier Inside Armored Vehicle

Ukrainian Sniper Group Claims 1,700-Meter Kill of Russian Soldier Inside Armored Vehicle

by SOFX Staff Writer
May 29, 2025
0

A Ukrainian sniper reportedly struck a Russian armored personnel carrier (APC) from 1,700 meters away during an enemy assault operation...

ADVERTISEMENT
ADVERTISEMENT
Next Post
Paris Court Convicts Lafarge of IS Financing, Orders €30M Asset Seizure 26 Times Its Fine

Paris Court Convicts Lafarge of IS Financing, Orders €30M Asset Seizure 26 Times Its Fine

Air Force Names Microreactor Sites as Pentagon Launches Economic Defense Unit

Air Force Names Microreactor Sites as Pentagon Launches Economic Defense Unit

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz