Fraudster hacked hotel system, paid 1 cent for luxury rooms, Spanish cops say
- Reference: 1771439474
- News link: https://www.theregister.co.uk/2026/02/18/fraudster_hotel_hack_one_cent_luxury_room/
- Source link:
"This cyberattack was specifically designed to alter the payment validation system, and this is the first time we have detected a crime using this method," Spain's National Police [1]told media outlets .
The man, a 20-year-old Spanish national, was arrested while staying at a Madrid hotel with a four-night reservation that carried a €4,000 ($4,716) price tag – unless you hacked the payment system, as this fraudster did.
[2]
According to the cops, he stayed at this hotel several times, costing the business more than €20,000 ($23,608) in losses.
[3]
[4]
Police [5]began investigating the suspect earlier this month after an unnamed online booking website reported suspicious activity. The transactions appeared normal, indicating the man paid the full amount – at first.
[6]Moon hotel startup hopes you get lunar lunacy, drop $1M deposit for 2032 stay
[7]Kaspersky: RevengeHotels checks back in with AI-coded malware
[8]Polish cops nab 47-year-old man in Phobos ransomware raid
[9]Payroll pirates are conning help desks to steal workers' identities and redirect paychecks
Days later, however, when the site transferred the actual amount paid to the hotel, the payment-validation scam surfaced, indicating that the crook paid just one cent for rooms costing €1,000 ($1,179) per night.
Adding insult to injury, police said that the man also consumed mini-bar bottles and sometimes left those bills unpaid, too.
While he may be facing a free stay at a mini-bar free, unluxurious facility for his alleged crimes, we have an idea for his next big vacay, post-prison: an inflatable moon hotel.
[10]
The [11]definitely-going-to-happen hotel , slated to open in 2032, requires a deposit of either $250,000 or $1 million. No word on whether GRU Space, the hotel's operators, have received any one cent deposits – yet. ®
Get our [12]Tech Resources
[1] https://www.insidenova.com/news/national/spanish-police-arrest-hacker-who-booked-luxury-hotels-for-one-cent/article_9dacbe7b-a545-54d2-b8ac-51eec390e047.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aZZEihlWRpXa-EiSsOnICAAAAE0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZZEihlWRpXa-EiSsOnICAAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aZZEihlWRpXa-EiSsOnICAAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.france24.com/en/live-news/20260218-spanish-police-arrest-hacker-who-booked-luxury-hotels-for-one-cent
[6] https://www.theregister.com/2026/01/13/moon_hotel_startup_reservation/
[7] https://www.theregister.com/2025/09/23/kaspersky_revengehotels_checks_back_in/
[8] https://www.theregister.com/2026/02/17/poland_phobos_ransomware_arrest/
[9] https://www.theregister.com/2026/02/11/payroll_pirates_business_social_engineering/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZZEihlWRpXa-EiSsOnICAAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2026/01/13/moon_hotel_startup_reservation/
[12] https://whitepapers.theregister.com/
Greed, plus a belief that he is better than anyone else and can and will get away with it forever. Evidently not!
The old maxim of ‘quit when you’re ahead’ applies here; alas greed gets in the way.
"hard to believe he's clever enough to get one over on the payment processing system and not clever enough to not hit the same place several times!!!"
And staying multiple nights at a time.
If the billing was heavily discounted rather than free, nobody may have noticed. Could have been a coupon, points, package deal, etc. Creating a coupon code in the system and using that to get a top end room for budget pricing would have been a better hack.
The "loss" by the hotel is really their housekeeping and mini bar since I'd be amazed if the super expensive rooms are booked solid. We all know that a £9 bottle of water doesn't cost them more than 50p and a tiny bag of crisps about the same.
Someone give the boy a job
All he needs is a good boss to put that brain to work
Cyber attack?
Or faulty website?
Re: Cyber attack?
whynotboth.jpg?
Five stars
I hope he at least had the style to leave them good reviews
Re: Five stars
"I hope he at least had the style to leave them good reviews"
Great room, friendly staff, lots of amenities. The prison sentence is my only complaint.
Similar-ish thing happened to me
Though the hack in the article was probably more sophisticated, I had a customer using PayPal who replicated what PayPal sends back to me with a legitimate order. They paid $0.01 so that an actual order was raised, but managed to send me something that told me it was the correct amount. As I'm selling software registration codes, I sent the code before I realised, so that was something I couldn't take back. It only happened once, and I've changed the system now, and blocked the code so it can't be used again. I considered more robust checks, but most of those would have involved not trusting valid customers, so the potential push-back and loss of sales from that was not worth it, much like over-aggressive copy protection on software in years gone by.
Wait a second...
didn't The Stainless Steel Rat pull this off decades ago?
Re: Wait a second...
No he did it centuries from now
hard to believe he's clever enough to get one over on the payment processing system and not clever enough to not hit the same place several times!!!
MIND BOGGLING