CSIDB logo
Incident

Booking.com

Incident posture

Attack window
Apr 2026
Location
Netherlands
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 23:46

Linked entities

Victim
Booking.com
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Apr 2026
Resolved
Pending

Summary

Booking.com reported that unauthorized third parties accessed some guests’ booking information, including names, email addresses, phone numbers, booking details and any data shared with accommodation providers, while confirming that financial information remained secure. The company said it contained the activity, updated the PIN numbers for the affected reservations and notified the impacted customers. The incident adds to a pattern of security challenges for the platform, following earlier phishing‑related breaches that resulted in regulatory fines and a notable rise in travel‑related scams targeting its users.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or before April 14 2026, Booking.com noticed suspicious activity involving unauthorized third parties accessing some guests' booking information. The company confirmed the breach on Monday (April 14 2026) and stated that upon discovery they took action to contain the issue. They updated the PIN number for the affected reservations and informed the guests via email. The email explained that the accessed information could include booking details, names, email addresses, phone numbers, addresses, and any data shared with accommodation providers, but that financial information was not accessed.

Booking.com, headquartered in Amsterdam and founded in 1996, provides access to over 30 million accommodation listings worldwide. The breach is part of a pattern of cyber incidents affecting the company, including a 2025 increase in scam attempts where customers were asked for payment information to verify trips, and a 2018 phishing attack that compromised hotel employee credentials in the UAE and led to unauthorized access to booking data for over 4,000 customers, resulting in a fine from the Dutch privacy regulator for delayed reporting. Additionally, the company noted a 900 percent rise in travel scams from 2023 to 2024 preceding this incident.

The company stated that security measures were put in place to contain the breach and that they continue to monitor the situation. No further details about the number of affected customers or the specific attack vector have been disclosed. The incident adds to the series of cybersecurity challenges faced by online travel platforms, highlighting the sensitivity of booking data and the potential for follow‑on misuse.

Sources

Sources available to members: 2 sources.

CSIDB