惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
L
LangChain Blog
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
The Cloudflare Blog
J
Java Code Geeks
Google DeepMind News
Google DeepMind News
Recent Announcements
Recent Announcements
Microsoft Azure Blog
Microsoft Azure Blog
Y
Y Combinator Blog
有赞技术团队
有赞技术团队
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
Martin Fowler
Martin Fowler
小众软件
小众软件
量子位
月光博客
月光博客
P
Proofpoint News Feed
IT之家
IT之家
腾讯CDC
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
雷峰网
雷峰网
V
Visual Studio Blog

The Register - Security

Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw ShinyHunters claims dump puts 119K Vimeo emails in the wild
Booking.com warns of possible reservation data exposure
Carly Page Carly Page · 2026-04-13 · via The Register - Security

Cyber-crime

Booking.com warns reservation data may have checked out with intruders

Travel giant says names, contact details, dates, and hotel messages potentially exposed

Booking.com is warning customers that their reservation details may have been exposed to unknown attackers, in the latest reminder that the travel giant still can't quite keep a lid on the data flowing through its platform.

The company began emailing affected users over the past few days, saying that "unauthorized third parties" may have accessed booking information tied to their accounts. The data in question appears to include names, contact details, reservation dates, and any messages exchanged with hotels through the platform.

While the company is keen to insist that financial data wasn't accessed, it's far less forthcoming about how many customers are affected. Booking.com did not respond to The Register's request for comment.

In an email to affected users, seen by The Register, Booking.com said it had detected suspicious activity, contained the issue, and reset booking PINs as a precaution. Customers have been told to watch out for phishing attempts, a notable risk given the nature of the exposed data.

"We recently noticed suspicious activity affecting a number of your guests' reservations," the email reads. "This may have led to unauthorized third parties being able to access the booking information for these bookings. We are emailing guests informing them that, in order to secure their booking, the PIN number for their booking confirmation has been changed."

It's not a credit card-skimming free-for-all, but it is exactly the kind of data that makes a convincing phishing email far too easy. The platform's built-in messaging system has been abused for this before, often after hotel accounts were compromised, turning legitimate conversations into a delivery channel for payment scams.

The company has not said how the data was accessed, whether this was tied to a compromise of partner systems, or how long the exposure lasted before it was spotted.

It also isn't the first time Booking.com has found itself in this position. In 2021, Dutch regulators fined the company €475,000 after a breach exposed the personal data of more than 4,000 customers, including credit card details in some cases, following a compromise of hotel staff logins. That incident hinged on attackers gaining access through the supply chain rather than breaking into Booking.com directly, a pattern that has cropped up repeatedly across the travel sector.

If this latest compromise follows a similar script, the breach itself may end up being only half the story. The more immediate risk is follow-on phishing, as attackers use real booking data to craft messages that look legitimate enough to slip past both users and basic security checks. ®