Hotel bookings and phishing

A hotel-booking message asks for another payment: how to detect and respond to phishing

A message may know the real hotel, dates, and price yet still link to a fake page asking you to confirm the booking or pay again. It may arrive by email, W

Leer en español

A message may know the real hotel, dates, and price yet still link to a fake page asking you to confirm the booking or pay again. It may arrive by email, WhatsApp, or even through a compromised property account inside a platform.

EXECUTIVE SUMMARY

What decision-makers should know

A message may know the real hotel, dates, and price yet still link to a fake page asking you to confirm the booking or pay again. It may arrive by email, W

    Correct booking details do not make the message authentic

    A scam may cite your name, property, dates, price, and booking number. Spain’s INCIBE has documented cases in which a property account on a booking platform was compromised and false messages arrived through a messaging service the victim recognized. Professional appearance, accurate information, or an existing conversation therefore does not establish trust.

    Treat urgency as a warning: confirm within hours, prevent cancellation, fix a rejected card, or receive a supposed refund. Booking.com says phishing commonly asks travelers to resubmit payment information to keep a booking. It also says it will not request card details by email, phone, text, or WhatsApp or demand a bank transfer different from the payment policy in the confirmation.

    Do not click, download, or call the number in the message. Open the app or type the official address manually, check status and payment policy in the booking, and contact support there. To reach the hotel, use a number in the authentic confirmation or verified website—not a sponsored search result or the contact that sent the demand.

    • Complete message, sender, and time
    • Authentic booking and payment policy
    • Visible URL without opening it
    • Channel where the message arrived
    • Amount and requested action

    Separate the traveler problem from the property problem

    For the traveler, first determine whether credentials, card data, identity documents, or a code were entered and whether charges occurred. Save screenshots, the message, URL, receipts, and the booking page without revisiting the fake site. Do not impulsively cancel a legitimate stay; verify its status with the platform and property through official channels.

    For a hotel, the campaign may use a lookalike domain, spoofed email, or genuine access to a reservation portal. Review users, sessions, devices, mail rules, integrations, profile changes, sent messages, and access held by staff or vendors. Change credentials from clean systems, enable additional authentication, revoke unknown access, and preserve logs before they disappear.

    Do not publicly blame Booking.com, the hotel, or an employee without evidence. A compromised account, external message, and cloned website are separate assets. Name a security lead and customer-contact lead, maintain one timeline, and record which reservations or recipients may be exposed without gathering unnecessary personal data.

    If you clicked, shared information, or paid

    If you only opened the page, close it, avoid downloads, and obtain device-specific security guidance. If you entered a password, change it immediately from a clean device, review sessions and reuse, and enable two-factor authentication. Booking.com advises resetting the account password and enabling 2FA when someone believes information was shared with a scammer.

    If you supplied card information or see charges, contact the bank or provider immediately through a verified number, explain the fraud, and follow its instructions on blocking, replacement, disputes, and monitoring. Preserve amounts, times, merchants, and references. No agency can promise reimbursement; options depend on payment method, institution, country, evidence, and elapsed time.

    Report the incident to platform support and the property through official channels. In Spain, INCIBE provides cybersecurity guidance, and the case may require the bank, police, or other authorities. Use equivalent channels elsewhere. Identity documents, losses, threats, or a possible breach require professional assessment; this guide does not determine legal obligations.

    How a hotel should warn guests without increasing harm

    Once risk is verified, the property should promptly warn potentially affected bookings through authentic channels. State which channel or URL is not yours, which payments will not be requested, how to check the booking, and where to get help. Do not link to the false domain or attach forms; a phishing warning that looks like phishing will be less effective.

    Add a dated notice to the official website and profiles, prepare scripts for reception and customer service, and coordinate with the platform. Never publish guest names, stay dates, booking numbers, or screenshots. Report each fake domain, ad, phone number, or profile separately to the relevant provider and preserve references and decisions.

    ReputationGeo.ai can organize evidence, map messages and domains, prepare bilingual reports and warnings, and monitor reappearances. Platforms, hosts, registrars, banks, and authorities decide independently. We do not guarantee removal, blocking, identification, financial recovery, or timing. The response should combine security, privacy, and reputation without presenting an incomplete investigation as established fact.

    How to turn this guidance into a responsible plan

    Begin with evidence, not assumptions. Save the exact URLs, screenshots, publication dates, search phrases, review profiles and AI answers that are creating concern. Record where each item appears, who controls the source and whether the information is inaccurate, outdated, private, misleading or simply unfavorable. These distinctions matter because removal, correction, response, suppression and monitoring are different remedies. A credible adviser should explain those differences before recommending work or discussing timing.

    Next, define the audience and the decision at risk. A result seen by prospective clients in Spain may require different language, sources and local signals from a result affecting investors in the United States. Decide which names, brands, locations and search questions matter most. Prioritization prevents a campaign from becoming a vague attempt to control the internet and turns it into a measurable program focused on accuracy, trust and discoverability.

    Evidence, people and measurements to prepare

    Create a baseline before changes begin. It can include the first two pages of Google for agreed searches, ratings and review volume, visibility of owned pages, recurring themes in AI answers and the status of platform or publisher requests. Keep personal data to the minimum necessary and share sensitive documents only through an agreed secure process. If a legal right may apply, involve qualified counsel in the relevant jurisdiction; reputation strategy does not replace legal advice.

    Assign an owner for approvals, factual verification and customer responses. Review progress consistently, but do not judge the program by one daily ranking. Useful measures include corrected or removed items, response completion, the share of credible owned and independent sources, search-result composition, branded query trends and whether public information answers real questions. The objective is a more accurate and resilient digital record, not an artificial promise that criticism will disappear.

    Keep a decision record, not just a list of links

    For every material item, record the exact source, the factual concern, the person responsible for verification, the proposed route and the reason that route is proportionate. Include the date of any request, response deadline, platform reference number and next review date. This record prevents duplicate or contradictory reports and helps a new decision-maker understand why an item was corrected, challenged, answered, monitored or left alone.

    A sound record also separates confirmed facts from interpretations. Label legal questions for qualified counsel, service failures for operational owners and public explanations for communications review. If an item changes, preserve the before-and-after evidence without collecting more personal data than necessary. This discipline is especially important when search engines and AI systems update unpredictably: it shows what actually changed and avoids claiming credit for movements that may have several causes.

    • Source, URL, date and affected search or prompt
    • Verified facts, disputed claims and supporting evidence
    • Chosen route, owner, status and next review date
    • Privacy, amplification and escalation risks

    Related ReputationGeo.ai services

    Use these service pages to distinguish image removal, broader content removal and search delisting before choosing a route.

    Frequently asked questions

    Official sources and further reading

    Rules and procedures change. Check the current official guidance before submitting a request.

    The practical next step

    Document the relevant URLs, searches and facts before acting. A responsible plan should separate what can be corrected or removed from what needs response, suppression or monitoring. The correct approach depends on the source, market and evidence.

    Apply the guide to your specific situation.

    Send the public links and the market affected. We will explain the realistic options and dependencies.

    Protected by a hidden spam-control field. No advertising trackers are loaded with this form.