Last Update: 08/01/2026 at 1:00 PM EST

Booking.com Reservation Breaches

Coverage from WebProNews, The Guardian, and others

Articles

46

Active Days

2797

The Topic

Booking.com Reservation Breaches topic image

This topic centers on Booking.com and related travel booking portals exposing traveler data through breaches, suspicious access, or insecure third-party systems. The disclosed information commonly includes names, email addresses, phone numbers, addresses, reservation details, and, in some cases, accommodation communications or passport images. The main significance is not direct financial theft but the way booking data can be reused for phishing, reservation hijacking, and other targeted scams.

First Article: 11/30/18

Latest Article: 07/27/26

Summary

  • Booking.com repeatedly appears as the central platform, with multiple disclosures tied to unauthorized access to reservation-linked data.
  • Exposed data is usually enough to support convincing phishing or reservation-hijacking scams, even when financial data is not reported as accessed.
  • The incidents affect traveler identity and trip details, including names, email addresses, phone numbers, addresses, and booking history.
  • Booking.com and affected portals responded by containing access, updating reservation PINs, and notifying users.
  • The material points to a broader pattern of travel-booking systems being used as a scam surface after initial data exposure.
  • A third-party UK visa portal adds a related privacy exposure pattern involving passport scans and selfie images stored in public cloud storage.

History

06/07/2026

The story has shifted from a Booking.com-centered pattern of travel-data exposure to a broader hospitality-breach cluster, with a new Dutch hotel incident showing shared software can propagate exposure across many properties. It also now includes stronger enforcement context, including prior regulatory penalties and a fresh GDPR investigation.

05/30/2026

The story has broadened from Booking.com reservation breaches into a wider travel-data exposure pattern that now includes a UK visa portal leaking passport scans and selfies. The framing has also shifted toward vendor and cloud-security failures, with incomplete disclosure emerging as a recurring concern.

Featured

Timeline: 2797 Days

2018Jan 1Mar 5May 28Jul 30Oct 22Dec 242019Jan 1Mar 5May 28Jul 30Oct 22Dec 242020Jan 1Mar 4May 27Jul 29Oct 21Dec 232021Jan 1Mar 5May 28Jul 30Oct 22Dec 242022Jan 1Mar 5May 28Jul 30Oct 22Dec 242023Jan 1Mar 5May 28Jul 30Oct 22Dec 242024Jan 1Mar 4May 27Jul 29Oct 21Dec 232025Jan 1Mar 5May 28Jul 30Oct 22Dec 242026Jan 1Mar 5May 28Jul 30Oct 22Dec 24

Additional Articles

⭐⭐⭐⭐⭐

NDTV05-16-2026
Reqrea’s Tabiq hotel check-in platform exposed over one million passports and selfie verification photos online after an Amazon cloud bucket misconfiguration was discovered in Japan.
Techzine Global / Colin Baak06-03-2026
Hospecs reported a breach impacting at least 100 Dutch hotels, exposing reservation data and enabling phishing and fake payment requests for guests.
Join the Claim05-29-2026
Researchers reported a data leak in the UK Visa Portal third-party travel authorization website in the UK, exposing up to 100,000 identity documents in public cloud storage.
Captain Compliance06-06-2026
Hospecs confirmed a shared booking software breach on or around June 3, 2026, exposing reservation data for at least 100 Dutch hotels and prompting AP investigation.
Security Affairs / Pierluigi Paganini05-18-2026
Reqrea secured a misconfigured Amazon cloud storage bucket after researcher Anurag Sen and TechCrunch alerted JPCERT to worldwide exposure of passport and ID documents.
Security Affairs / Pierluigi Paganini05-28-2026
TechCrunch reported a third-party UK visa portal exposed at least 100,000 passport scans and GPS-bearing selfies on a public Amazon storage server before bucket security.
Class Action U07-25-2026
The LINE Los Angeles notified Koreatown guests in July 2026 after a September 2025 unauthorized network access incident may have exposed personal information filed with the California Attorney General.
Emery Reddy07-27-2026
LINE Los Angeles filed a California Attorney General data breach notice on July 24, 2026 after discovering unauthorized network access in September 2025.
WJAR04-15-2026
Booking.com disclosed a data breach in which personal data such as names, addresses, and reservations were exposed, raising risk of personalized phishing scams.
AOL.com04-22-2026
Booking.com disclosed a breach after suspected third party access to reservation data, prompting customer notifications and PIN updates.
Security Boulevard / Jack Poller04-30-2026
KasadaIQ reported Booking.com reservation data exposure and described Dabai Guarantee Telegram marketplaces as AI-driven fraud markets expanded in Q1 2026.
Forbes / Davey Winder04-14-2026
Booking.com reported a third-party incident involving unauthorized access to some reservation records and issued PIN code changes after containment actions.
CX Today / Nicole Willing04-14-2026
Booking.com confirmed unauthorized access to customer booking data after partner-targeted phishing and spoofed emails, with alerts and reservation PIN updates following containment.
RENTAL12 / Floriana Panvini Rosati05-31-2026
Booking.com notified customers on 13 April 2026 that compromised hotel-partner accounts enabled reservation-data access used for reservation-hijack payment scams.
Slashdot04-13-2026
Booking.com reported a reservation-data breach and introduced new reservation PINs after suspected hacker access potentially exposed customers in affected reservations.
Medium04-15-2026
Booking.com confirmed in April 2026 that unauthorized third parties accessed reservation data, exposing PII used for targeted phishing and impersonation.

⭐⭐⭐

BleepingComputer / Bill Toulas04-13-2026
Booking.com said unauthorized third parties may have accessed reservation-associated information, prompting PIN resets and direct email alerts to impacted users.
Join the Claim04-17-2026
Booking.com confirmed a reservation-data breach after unauthorized access to booking information, notified customers, updated PINs, and warned about reservation hijack fraud scams.
AltexSoft04-14-2026
Booking.com disclosed unauthorized access to reservation-linked traveler personal data over the weekend and began notifications while stating payment data was not exposed.
HolidayPirates05-19-2026
Booking.com confirmed an unauthorized reservation-information breach and warned travellers about phishing messages using booking details delivered via email and WhatsApp.
Cybersecurity Insiders / Naveen Goud04-20-2026
Booking.com reported a potential customer data breach in the Netherlands, after UK users reported phishing emails and messages aimed at password resets.
Security Affairs / Pierluigi Paganini05-12-2026
BWH Hotels disclosed between October 2025 and April 2026 unauthorized access to a guest reservation web application, exposing names, contact details, and booking information.
Connexion France05-18-2026
Gîtes de France reported a cyberattack affecting up to 389,000 European clients after May 18 breach notifications in France.
Databreaches06-14-2026
BWH Hotels warned hotel guests about fraudulent messages after unauthorized access to reservation-associated contact data between October 14, 2025 and April 22.
Daily Hive04-17-2026
Booking.com notified customers in response to a suspected data breach involving unauthorized access to reservation-linked personal information, while stating payment data was not accessed.
Panda Security Mediacenter / Emil Bachev04-22-2026
Booking.com confirmed a data breach on 2026-04-12 affecting reservation details and contact information, while stating payment information was not accessed.
TechRadar / Sead Fadilpašić04-14-2026
Booking.com notified users in the 2020s after suspicious activity tied to reservations may have exposed booking and contact details, leading to PIN resets and phishing warnings.
JD Supra04-22-2026
Booking.com notified travelers of unauthorized access to booking data, issued new PINs, and left breach scope and remediation details unspecified.
Help Net Security04-14-2026
Booking.com notified customers after suspicious activity raised concerns about unauthorized access to reservation contact details, with notifications and reservation PIN updates following the discovery.
Tom's Guide / Scott Younker04-13-2026
Booking.com confirmed in the 2020s that unauthorized third parties accessed reservation-linked customer data, triggering containment, PIN updates, and guest notifications.
Techzine Global / Erik van Klinken04-13-2026
Booking.com confirmed a Sunday evening data breach after suspicious activity, warning that unauthorized third parties may have accessed customer reservation details and notifying affected guests.
Techzine Global / Erik van Klinken04-13-2026
Booking.com confirmed a Sunday evening data breach after suspicious activity potentially exposed reservation and contact data for some guests.
CISO Platform04-14-2026
On April 13, 2026, Booking.com confirmed unauthorized access while Anodot and OpenAI faced cloud and supply-chain incidents, alongside actively exploited vulnerabilities affecting privacy-relevant data.
Rtdna11-30-2018
Marriott discloses a data breach affecting up to 500 million Starwood guests dating back to 2014 in the online booking system.
Skift / Adriana Lee04-13-2026
Booking.com notified customers after hackers accessed reservation data over a weekend, potentially exposing names and contact details and prompting PIN resets and phishing warnings.
TravelAwaits04-20-2026
Booking.com reported a reservation hijack on April 13, 2026, exposing user personal data and booking history while stating no financial data access occurred.
Security Affairs / Pierluigi Paganini04-13-2026
Booking.com notified customers after suspected unauthorized third-party access to reservation-linked personal data, issued PIN resets and phishing warnings, and said no payment data was accessed.
Wired / David Nield05-10-2026
Booking.com reported an April 2026 breach with leaked contact and reservation details that facilitates reservation hijacking impersonation scams.
Doctor Of Credit / William Charles04-13-2026
Booking.com informed customers via email in 2026 that unauthorized parties may have accessed reservation booking information and updated reservation PIN numbers.
Yahoo Travel04-14-2026
Booking.com disclosed an unauthorized third-party incident affecting some guests' booking details, detected and contained after suspicious activity, with reservation PIN code resets and user guidance.
News24 / Maya Fisher-French04-13-2026
Booking.com issued new reservation PINs after unauthorized third parties accessed booking-linked data, enabling impersonation scams via WhatsApp, email, and SMS.
Xact IT Solutions06-20-2026
UK Ministry of Justice confirmed May 2025 Legal Aid Agency data breach after online portal intrusion exposed about 2.1 million applicants since 2010.
View from the Wing / Gary Leff05-04-2026
Scammers in San José, Costa Rica used Booking.com reservation data to impersonate Hilton staff and collect payments outside standard booking channels.