← Booking.com

2026 Booking.com — guest reservation data accessed (phishing risk; Apr; no payment cards per company)

2026 Unknown records affected Share on X

Data compromised

Names, emails, phones, addresses, booking/itinerary details, hotel messaging content (per company and press)

Technical writeup

In mid-April 2026, Booking.com emailed customers—including in Ireland and other markets—that unauthorized third parties may have accessed booking information tied to some reservations. Public reporting (e.g., SecurityWeek, The Register) quoted the company stating it detected suspicious activity, contained the issue, and reset booking PINs as a precaution. Disclosed data categories included names, email addresses, phone numbers, physical addresses, reservation details, and content shared with accommodations via the platform’s messaging; Booking.com publicly emphasized that payment card data was not accessed and that customer accounts were not breached in the sense of credential compromise at the user account layer—while leaving technical root cause (direct platform vs. partner/hotel path) ambiguous in early coverage. The incident was widely framed as a phishing and social-engineering risk because accurate trip details make lures more convincing.

Root cause

Unauthorized access to guest booking/reservation data (exact vector not fully detailed in initial press)

References