Crime Hackers swipe Booking.com, several Japanese hotels

thomas

Unswerving cyclist
Admin
Joined
14 Mar 2002
Messages
21,050
Reaction score
18,903
Since last May, Japan has been plagued by phishing scams targetting Booking.com and other travel sites, affecting at least 68 hotels. The stolen information mainly involved foreign visitors. A security company found Russian hackers behind it: they usually pretended to be travellers or hotel staff. They obtained the hotel IDs and passwords to access Booking.com and then tricked the travellers into entering their credit card information on a fake site.


The email contained a link that, once clicked, triggered a virus infection, allowing the hacker to obtain hotel IDs and passwords when accessing Booking.com fraudulently. The hackers then used these credentials to gain unauthorized access to Booking.com and sent messages to travellers pretending to be hotel staff. The messages falsely claim that "advance payment is required" and then force travellers to enter their credit card numbers and other details into a fake site that resembles Booking.com to steal the information. [...] The company did not reveal the global scale or estimated damages but said some of the 6.6 million facilities that use Booking.com were compromised.



 
As reported on Saturday, over 100 Japanese hotels have been targeted by email fraudsters attempting to hijack clients' credit card data via the reservation platform Booking.com. Several hotels reported financial losses for guests due to unauthorized access to their credit card information. The Japan Tourism Agency has directed Booking.com's local subsidiary in Japan to probe the matter thoroughly.

Fraudsters send emails to Japanese hotels to access their Booking.com management system. The email contains a link, which infects a computer once clicked. The hackers then steal the business's Booking.com credentials to send fraudulent payment requests to customers with reservations, telling guests their stay will be canceled without advance payment. Customers are then directed to input their card details into a fake website. In one case in August last year, a hotel became ensnared by the fraudsters when an employee clicked on a link of what the sender claimed was a list of a customer's daughter's food allergies. An official at the hotel said the imposters "exploited our desire to do our best to fulfill customers' wishes." Similar scam cases were first confirmed in Europe in 2022, with incidents later spreading to the United States, Asia and Oceania-based hotels.

 
I've been getting random "verification" emails from booking.com lately. Despite traveling I have been using other platforms to make my reservations and never tried to use booking or clicked on any of the emails

But I made a last minute reservation through Agoda the other day, and when I arrived at the hotel they said it had been made through... booking.com

It's the Scooby mask reveal moment
 
Back
Top Bottom