Booking.com customers have been warned of a “well-designed scam” that has seen account details sold on the dark web.
Cybersecurity firm Secureworks said criminals are targeting the website’s partner hotels to steal user details.
They then send phishing emails to the customers, claiming their reservation will be cancelled if they do not provide payment information urgently.
Rafe Pilling, director of threat intelligence at Secureworks, said the tactic was seeing a “high success rate”, and Booking.com said it was aware some of its partners had been affected in recent months.
“While this breach was not on Booking.com, we understand the seriousness for those impacted, which is why our teams work diligently to support our partners in securing their systems as quickly as possible and helping any potentially impacted customers accordingly, including with recovering any lost funds,” it said.
The scam unfolds in two phases, starting with hotels themselves being targeted by scam emails.
They often claim to be from a guest who has left valuable documents during their stay, who then sends a follow-up email directing the hotel to a Google Drive link purporting to show an image of the lost item.
The link actually contains malware called Vidar Infostealer, which allows the criminals to access the Booking.com account portal that people use to make their reservations.
From there, they can target the customers.
Advertisement
Look out for ‘sense of urgency’
In one case involving a hotel in Scotland, a receptionist was duped by a scam caller who claimed to want to book a room for herself and her child with serious allergies.
They said it would be easier to email a document outlining the child’s allergies to determine whether the hotel could accommodate them, and the attachment contained the malware.
It gathered details of all the hotel’s Booking.com customers and sent them fraudulent emails saying they had 24 hours to pay.
Jude McCorry, chief executive of Scotland’s Cyber and Fraud Centre, told Sky News it was a “well-designed scam” that less tech-savvy people would find it “very difficult” to identify.
She said a “sense of urgency” in demanding money was often a tell-tale sign that something could be wrong.
Secureworks has found Booking.com credentials being sold on dark web forums for up to $2,000 (£1,576).
It said the scam was not an easy one to close down because it relies on Booking.com and its partner hotels having effective controls in place, as well as employees and customers recognising the threat.
The company has recommended that hotels make staff aware and teach them how to identify such attacks, while customers should use multifactor authentication to protect their accounts.
They should also question any emails or app messages requesting payment details, and contact Booking.com or the hotel directly if they have concerns.
Booking.com said online fraud was a “pressing issue across many sectors” and the company has made “significant investments to limit the impact of these ever-evolving tactics”.
“Due to the rigorous controls and the machine learning capabilities we employ, we are able to detect and block the overwhelming majority of suspicious activity before it impacts our partners or customers,” it added.
“We have also been sharing additional tips and updates with our partners about what they can do to protect themselves and their businesses, along with the latest information on malware and phishing so that they are as up-to-date as possible on the latest trends that we’re seeing.
“In terms of some practical steps that customers can take to remain safe online, we recommend vigilance and that people carefully check the payment policy details outlined in their booking confirmation.
“If a property or host appears to be asking for payment outside what’s listed on their confirmation, they should reach out to our customer service team for support.
“Also, it’s good to remember that no legitimate transaction will ever require a customer to provide their credit card details by phone, email, or text message (including WhatsApp).”
Marnie’s first serious relationship came when she was 16-years-old.
Warning: This article contains references to strangulation, coercive control and domestic abuse.
She was naturally excited when a former friend became her first boyfriend.
But after a whirlwind few months, everything changed with a slow, determined peeling away of her personality.
“There was isolation, then it was the phone checking,” says Marnie.
As a survivor of abuse, we are not using her real name.
“When I would go out with my friends or do something, I’d get constant phone calls and messages,” she says.
“I wouldn’t be left alone to sort of enjoy my time with my friends. Sometimes he might turn up there, because I just wasn’t trusted to just go and even do something minor like get my nails done.”
Image: The internet is said to be helping to fuel a rise in domestic abuse among teens. Pic: iStock
He eventually stopped her from seeing friends, shouted at her unnecessarily, and accused her of looking at other men when they would go out.
If she ever had any alone time, he would bombard her with calls and texts; she wasn’t allowed to do anything without him knowing where she was.
He monitored her phone constantly.
“Sometimes I didn’t even know someone had messaged me.
“My mum maybe messaged to ask me where I was. He would delete the message and put my phone away, so then I wouldn’t even have a clue my mum had tried to reach me.”
The toll of what Marnie experienced was only realised 10 years later when she sought help for frequent panic attacks.
She struggled to comprehend the damage her abuser had inflicted when she was diagnosed with PTSD.
This is what psychological abuse and coercive control looks like.
Please use Chrome browser for a more accessible video player
2:56
‘His hands were on my throat – he didn’t stop’
Young women and girls in the UK are increasingly falling victim, with incidents of domestic abuse spiralling among under-25s.
Exclusive data shared with Sky News, gathered by domestic abuse charity Refuge, reveals a disturbing rise in incidents between April 2024 and March 2025.
Psychological abuse was the most commonly reported form of harm, affecting 73% of young women and girls.
Of those experiencing this form of manipulation, 49% said their perpetrator had threatened to harm them and a further 35% said their abuser had threatened to kill them.
Among the 62% of 16-25 year olds surveyed who had reported suffering from physical violence, half of them said they had been strangled or suffocated.
Earlier this year, Sky News reported that school children were asking for advice on strangulation, but Kate Lexen, director of services at charity Tender, says children as young as nine are asking about violent pornography and displaying misogynistic behaviour.
Image: Kate Lexen, director of services at charity Tender
“What we’re doing is preventing what those misogynistic behaviours can then escalate onto,” Ms Lexen says.
Tender has been running workshops and lessons on healthy relationships in primary and secondary schools and colleges for over 20 years.
Children as young as nine ‘talking about strangulation’
Speaking to Sky News, Ms Lexen says new topics are being brought up in sessions, which practitioners and teachers are adapting to.
“We’re finding those Year 5 and Year 6 students, so ages 9, 10 and 11, are talking about strangulation, they’re talking about attitudes that they’ve read online and starting to bring in some of those attitudes from some of those misogynistic influencers.
“There are ways that they’re talking about and to their female teachers.
“We’re finding that from talking to teachers as well that they are really struggling to work out how to broach these topics with the students that they are working with and how to make that a really safe space and open space to have those conversations in an age-appropriate way, which can be very challenging.”
Please use Chrome browser for a more accessible video player
4:58
Hidden domestic abuse deaths
Charities like Tender exist to prevent domestic abuse and sexual violence.
Ms Lexen says without tackling misogynistic behaviours “early on with effective prevention education” then the repercussions, as the data for under 25s proves, will be “astronomical”.
At Refuge, it is already evident. Elaha Walizadeh, senior programme manager for children and young people, says the charity has seen a rise in referrals since last year.
Image: Elaha Walizadeh, senior programme manager for children and young people at Refuge
“We have also seen the dynamics of abuse changing,” she adds. “So with psychological abuse being reported, we’ve seen a rise in that and non-fatal strangulation cases, we’ve seen a rise in as well.
“Our frontline workers are telling us that the young people are telling them usually abuse starts from smaller signs. So things like coercive control, where the perpetrators are stopping them from seeing friends and family. It then builds.”
Misogyny to violent behaviour might seem like a leap.
But experts and survivors are testament to the fact that it is happening.
It says human rights in the UK “worsened” in 2024, with “credible reports of serious restrictions on freedom of expression”, as well as “crimes, violence, or threats of violence motivated by antisemitism” since the 7 October Hamas attack against Israel.
On free speech, while “generally provided” for, the report cites “specific areas of concern” around limits on “political speech deemed ‘hateful’ or ‘offensive'”.
Sir Keir Starmer has previously defended the UK’s record on free speech after concerns were raised by Mr Vance.
In response to the report, a UK government spokesperson said: “Free speech is vital for democracy around the world including here in the UK, and we are proud to uphold freedoms whilst keeping our citizens safe.”
Image: Keir Starmer and JD Vance have clashed in the past over free speech in the UK. Pics: PA
The US report highlights Britain’s public space protection orders, which allow councils to restrict certain activities in some public places to prevent antisocial behaviour.
It also references “safe access zones” around abortion clinics, which the Home Office says are designed to protect women from harassment or distress.
They have been criticised by Mr Vance before, notably back in February during a headline-grabbing speech at the Munich Security Conference.
Ministers have said the Online Safety Act is about protecting children, and repeatedly gone so far as to suggest people who are opposed to it are on the side of predators.
Please use Chrome browser for a more accessible video player
5:23
Why do people want to repeal the Online Safety Act?
The report comes months after Sir Keir bit back at Mr Vance during a summit at the White House, cutting in when Donald Trump’s VP claimed there are “infringements on free speech” in the UK.
“We’ve had free speech for a very long time, it will last a long time, and we are very proud of that,” the PM said.
But Mr Vance again raised concerns during a meeting with Foreign Secretary David Lammy at his country estate in Kent last week, saying he didn’t want the UK to go down a “very dark path” of losing free speech.
Please use Chrome browser for a more accessible video player
The Trump administration itself has been accused of trying to curtail free speech and stifle criticism, most notably by targeting universities – Harvard chief among them.