Booking.com has sent a security notice to connectivity partners following reports of an increase in sophisticated fraudulent messages targeting employees through email, WhatsApp and social media.
These messages can look highly convincing and may attempt to obtain credentials, system access or reservation data. Booking.com notes that criminals target every place where reservation data can be accessed, including accommodation providers, tourism businesses and technology partners.
What Booking.com recommends
Key security measures:
- enable two-factor authentication (2FA) on every service that supports it
- keep antivirus and anti-phishing protection updated on computers and mobile devices
- watch for unexpected changes in accounts and systems
- check third-party platforms for unfamiliar users, unusual logins or suspicious data exports
- brief your team on phishing signs and never share credentials, even with someone claiming to be from Booking.com
What we recommend to MyRent users
If you receive an unexpected message about a Booking.com account, reservation, bank detail change or a request to sign in through a link, do not enter credentials until you have verified the request through official Booking.com channels.
The most important rule: never send passwords or other access credentials by email, WhatsApp or chat, regardless of who asks for them.
If you notice suspicious activity, change the password immediately, sign out unknown sessions where possible, review users with account access and contact the platform through its official support channels. Booking.com also recommends running antivirus and anti-malware checks and clearing browser cookies when compromise is suspected.
General rules for safer internet use
In addition to Booking.com’s recommendations, a few basic habits can reduce the risk of phishing, account theft and other online fraud:
General rules for safer internet use
- do not open unexpected links or attachments before checking the sender and domain
- verify the website address before entering a password, payment card or other sensitive information
- use a unique, strong password for every important service, ideally with a password manager
- enable 2FA and, where available, prefer stronger methods such as an authenticator app or passkey
- never approve changes to bank details, payouts or access credentials based only on an email or message; verify the request through another trusted channel
- regularly remove old or unnecessary user accounts and limit administrator rights to people who actually need them
- keep operating systems, browsers, mobile devices and business applications up to date
- avoid using public or shared computers for business accounts unless necessary, and always sign out afterwards
- be especially cautious when a message creates urgency, pressure or fear and asks you to click, pay or send information immediately
- if you are unsure whether a message is legitimate, do not reply to it; open the official website yourself or contact support using verified contact details