In mid-April 2026, Booking.com publicly warned users that unauthorized third parties may have accessed information tied to certain reservations: names, contact details, itinerary/booking information, and content shared with properties via in-platform messaging. Trade press quoted the company stating customer accounts were not breached in the credential sense and that payment card data was not accessed, while emphasizing phishing risk—especially for travelers who received authentic-looking lures referencing real trips.
Canonical record: Booking.com 2026 on BreachHistory · Historical: 2018 UAE hotel credential scam
Sources: SecurityWeek, The Register