Login
You're viewing the front-end.social public feed.
  • Oct 5, 2026, 7:20 PM

    I fell for the Booking.com WhatsApp scam today. There has apparently been a #databreach at #bookingcom, which provides a little bit of truth to this "please verify your credit card now" scam. They knew my name, my phone number, the hotel I was staying at and the exact dates. That, a little bit of time pressure and a potential quick solution got me.

    I managed to complete the flow once, which according to them would only reserve the money. Something failed and I tried again. This time they were asking me to confirm the balance of my account for verification, and that finally triggered the alert for me.

    In retrospect, the originating WhatsApp number was located in Brazil (which was not where I was going). The name didn't match the name of the Hotel representative in the message, and the website's title was Booking.com, which didn't match the actual host name in the URL. I didn't notice.

    Approach shit like this calmly and don't let people push you to rash decisions.

    #Phishing #scam

    💬 9🔄 156⭐ 146

Replies

  • 💬 1🔄 0⭐ 12
  • Oct 5, 2026, 7:35 PM

    @alf149 I only have my pride to lose! 😂 I've had countless hours of e-learning about phishing and I consider myself somewhat IT sawwy, but when I thought I was about to lose my hotel booking, combined with the fact that they had some of my data, I was hooked.

    I'm already hearing about phone calls with AI-generated voices that sound like your children or partner - so far only abroad, but it's only a matter of time before we'll start to see cases like that here.

    Devious bastards.

    💬 1🔄 4⭐ 7
  • Oct 5, 2026, 9:19 PM

    @saustrup @alf149

    All of these trainings cannot prepare you for the real thing. And everybody is vulnerable from time to time and the bad guys just need luck with their timing. Hence "defense in depth" as a principle also in real life, i.e. minimizing the potential damage.

    💬 0🔄 0⭐ 1
  • 💬 0🔄 0⭐ 4
  • Oct 5, 2026, 7:39 PM

    @saustrup I got one of these also. Fortunately the name of the hotel was slightly off and I ignored them.

    💬 0🔄 0⭐ 1
  • Oct 5, 2026, 7:40 PM

    @saustrup The one thing I always keep at the forefront of my mind is "yes, it COULD happen to me". I think I'm smart but I'm pretty sure there are scammers out there who are smarter than me.

    💬 0🔄 0⭐ 2
  • Oct 5, 2026, 7:44 PM

    @saustrup

    This hat been going on with booking.com for years, and while they used to have a hotline and dealt with those cases, they now only have a useless chat bot.

    My wife almost fell for one of these scams last year, and booking.com didn't care, so we deleted our accounts...

    💬 0🔄 2⭐ 4
  • Oct 5, 2026, 8:36 PM

    @ckd @saustrup Booking. com ignored me when an attempt was made last year - two hotels from the same chain in different cities in Slovakia. The hotel chain wasn't that interested either.

    💬 1🔄 0⭐ 1
  • Oct 5, 2026, 8:47 PM

    @MikeFromLFE @ckd @saustrup I had this with a hotel in Stavanger and one in London. The first had all my details and crafted a fake payment page. The second sent a link to my WhatsApp on the day of check in.

    I don't think it's one big data breach, I think the hotel backend is just easy to social engineer into, and many hotels have poor security practices.

    Booking definitely doesn't care. I tried to report it, but there simply isn't any way to let them know.

    💬 1🔄 0⭐ 3
  • Oct 5, 2026, 8:49 PM

    @MikeFromLFE @ckd @saustrup And then an apartment I booked in Spain sent me a WhatsApp from an unknown number asking for a 200E deposit, and that turned out (after lots of confirming) to be totally legit, and they sent me the money right back after the holiday.

    I'm completely at sea with this industry.

    💬 0🔄 0⭐ 4
  • 💬 1🔄 0⭐ 2
  • Oct 6, 2026, 5:17 AM

    @cm @evawolfangel @sveckert Exactly. Last breach I saw mentioned was April 2026, but clearly it's pouring out continously. And - as someone else mentioned - it wasn't necessarily at Booking.com, but could theoretically be anywhere along the path from the end user to the hotel clerk.

    And regarding booking directly - I often do, especially if I know and trust the hotel, but sometimes convenience wins. I'm human.

    💬 0🔄 0⭐ 0
  • 💬 0🔄 0⭐ 1
  • 💬 0🔄 0⭐ 1
  • 💬 0🔄 0⭐ 0