The online bookings have now become the most widespread way to organize vacations and stays, thanks to the simplicity and speed offered by the leading booking platforms: yet, this established habit today is at the center of a new wave of cybercrime that is causing growing concern.
Veronica Leonardi, an engineer and board member of Cyberoo, highlights that the phenomenon is recording a significant growth, especially during the holiday period, when the number of bookings increases and, consequently, the opportunities for scammers to strike travelers also rise.
Phishing changes its face and exploits authentic booking data
According to what has been observed by the Cyberoo expert, the main change concerns precisely the level of sophistication of the scams: if in the past it was rather easy to spot a phishing attempt thanks to roughly written emails or suspicious addresses, today fraudulent messages contain real booking details.
Web criminals can send communications in which appear the name of the lodging, the dates of the stay, the reservation number, and even personal references of the traveler—authentic information that makes the message coherent with the reservation made and increases the risk that the user trusts and follows the instructions received.
As Veronica Leonardi notes, the real leap in the quality of these fraudulent campaigns lies precisely in the fact that the message “doesn’t look fake” uses real data and e-mail addresses that appear entirely plausible.
How cybercriminals are able to operate
The critical point, Leonardi explains, is not about a breach of Booking.com’s central systems, which are described as secure and state-of-the-art. The problem arises instead from the compromise of accounts of partner lodging facilities on online booking platforms, including the so-called OTAs, i.e., Online Travel Agencies.
When a cybercriminal manages to access the profile of a hotel or other lodging, they can use authentic booking data and exploit communication channels that, in the eyes of the customer, appear completely legitimate: in this way, the scammer can contact the traveler at the moment when they are most vulnerable, often just a few days before departure.
In this phase, indeed, the fear of losing the booking or of seeing the stay canceled can prompt many people to act impulsively, making an additional payment or completing a supposed verification requested via a link received by e-mail, chat, SMS, or WhatsApp.
How to defend yourself against the new online booking scams
Faced with such an evolution of cyber threats, Veronica Leonardi invites travelers to adopt some simple precautions that can make a difference.
The primary recommendation is never to use any links received through chat, e-mail, SMS, or WhatsApp to complete payments or verify a booking. When faced with urgent requests, especially if they involve money or payment confirmations, it is important to interrupt the flow of the communication and verify your booking directly by accessing exclusively the official app or the official site of the platform through the usual channels.
Leonardi also advises finally completing the purchase of the stay only using the Booking app or the official site and those of other OTAs, checking the reservation multiple times directly from these tools. In the case of large sums, it is advisable to contact the lodging using only verified contacts found on official sites, to ensure the transaction has gone through successfully.