News: 0181680656

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Booking.com Hit By Data Breach (pcmag.com)

(Monday April 13, 2026 @05:00PM (BeauHD) from the another-day-another-breach dept.)


Booking.com says hackers [1]accessed customer reservation data in a breach that may have exposed booking details, names, email addresses, phone numbers, addresses, and messages shared with accommodations. PCMag reports:

> On Sunday, users reported receiving emails from Booking.com, warning them that "unauthorized third parties may have been able to access certain booking information associated with your reservation." The [2]email suggests the hackers have already exploited customer information.

>

> "We recently noticed suspicious activity affecting a number of reservations, and we immediately took action to contain the issue," Booking.com wrote. "Based on the findings of our investigation to date, accessed information could include booking details and name(s), emails, addresses, phone numbers associated with the booking, and anything that you may have shared with the accommodation."

>

> Amsterdam-based Booking.com has now generated new PINs for customer reservations to prevent hackers from accessing them. Still, the incident risks exposing affected customers to potential phishing scams.

The [3]Australian Broadcasting Corporation and [4]several Reddit users say they received scam messages from accounts posing as Booking.com.



[1] https://www.pcmag.com/news/double-check-your-travel-reservations-bookingcom-hit-by-data-breach

[2] https://www.reddit.com/media?url=https%3A%2F%2Fi.redd.it%2Fl3mon6i7wrug1.jpeg

[3] https://www.abc.net.au/news/2026-04-13/booking-com-data-security-breach-personal-details/106557630

[4] https://www.reddit.com/r/Bookingcom/comments/1sjglxc/weird_email/



Surprised? (Score:5, Interesting)

by SumDog ( 466607 )

I interviewed for Booking back around .. 2016 I think? Everything was written in Perl. There were no plans to move to anything else. There were very few tests. Developers often pushed straight to production. The recruiter mentioned all of this up front, which was the only positive thing. I'm honestly surprised it's taken this long for there to be a data breach. The place sounded like a shit shop.

Re:Surprised? (Score:4, Informative)

by dskoll ( 99328 )

Perl itself is neither here nor there with respect to security. But lack of tests and pushing straight to production... those are WTFs.

Re:Surprised? (Score:4, Informative)

by higuita ( 129722 )

perl directly is not a issue, as long you understand what it is doing. Just because is not a hyped language anymore, it still works very well

No tests and push to prod are a problem.

About the hack, i have 4 reservations, yet i only received notification about one of them, that is strange. I have both older and newer reservations of that affected. Maybe it was just the interconnect with other platforms (airbnb? other house renting service?)

Re: (Score:1)

by Anonymous Coward

> Everything was written in Perl.

Perl really isn't that bad. I'd rather use a site written in Perl than [1]Next.js [bleepingcomputer.com] for example.

[1] https://www.bleepingcomputer.com/news/security/critical-react2shell-flaw-in-react-nextjs-lets-hackers-run-javascript-code/

hacking.com (Score:2)

by suso ( 153703 ) *

hacking.yeah

Booking contact support sucks (Score:4, Interesting)

by cristiroma ( 606375 )

Three weeks ago I did a reservation booking and immediately received a message from the "host" to pay for the room within the next 12 hours with a link leading to a booking.com clone website asking card details. It look really legit, except one strange message: "If you don't remember the sum to pay, just enter 350€". Even Google chrome detected this as scam and shown the red warning screen about the site being a phishing danger.

I've reported this issue to customer support (cloned site, screenshots) and their answer was "If you are not comfortable about entering your card details you can try to contact the property directly using their phone number". I wonder how it could have helped?

Lucky I could cancel the reservation without any penalty and I'm really thinking not to use booking in the future. They take the commission but can't even make a simple check about a property which is obviously a scam ...

Very unprofessional.

Re: (Score:3)

by Zocalo ( 252965 )

The issue here might be that the hotel is legit, but their internal reservation system has been compromised. They get the booking.com confirmation, enter it into their system to assign you the relevant room, and the scammers use that info to try and stiff you. The scammer has your details, and combined with the fact that it's a fresh booking, a made up request for some clarity/additional confirmation followed by a request for money is going to press all the buttons for an almost perfect phish.

It appare

"Nobody will ever need more than 640k RAM!" -- Bill Gates, 1981
"Windows 95 needs at least 8 MB RAM." -- Bill Gates, 1996
"Nobody will ever need Windows 95." -- logical conclusion