Booking.com Data Breach Exposes Andorran Customers to Phishing Scams
Booking.com confirmed a cyber breach leaking customer data, triggering targeted phishing attacks on Andorran hotels and residents via WhatsApp and email.
Key Points
- Unauthorized access leaked names, emails, phones, and booking details.
- Scammers send urgent WhatsApp and email phishing using real reservation info.
- Credit card and bank details unaffected; PINs reset for impacted accounts.
- Booking.com investigating with experts; advises using official app only.
Booking.com has confirmed a cybersecurity breach that exposed personal data of some customers, including Andorran hotels and residents with active bookings. Unauthorized third parties accessed names, email addresses, phone numbers, and reservation details, which scammers have since used in targeted phishing attempts.
Affected Andorrans report receiving fraudulent WhatsApp messages—and in some cases emails—demanding bank details under the guise of confirming reservations or preventing cancellations. The messages create urgency by referencing real booking information and include links designed to trick users into entering sensitive financial data.
The company stresses that credit card numbers and direct banking information remained secure. Primarily impacted are those who made reservations through the platform, as the leaked details enable highly personalized fraud campaigns.
In response, Booking.com reset security PINs for affected accounts, strengthened internal protections, and sent warnings to users about suspicious contacts. It advises checking issues only via the official app or website and avoiding links from unverified channels. An internal investigation, aided by external cybersecurity experts, is underway to pinpoint the breach's origin and full scope.
Andorran hotels have notified guests that they never request additional payments via messaging apps or external links. While the incident appears contained, the platform urges ongoing caution, as stolen data could fuel further scams in coming weeks. Authorities echo calls for vigilance amid persistent risks.
Related Articles
Other articles from Catalan-language sources about the same story:
- ARA•
El ciberatac massiu a Booking amb hotels d'Andorra no va afectar targetes de crèdit
- Diari d'Andorra•
Booking en alerta per una filtració de dades que afecta andorrans
- Altaveu•
Booking pateix una filtració de dades i afecta clients andorrans amb reserves actives
- El Periòdic•
Alguns hotels i ciutadans andorrans podríen estar afectats per un ciberatac a Booking.com amb phishing
- ARA•
Hotels i usuaris d’Andorra, afectats pel frau vinculat al ciberatac de Booking
- Diari d'Andorra•
Booking pateix una filtració de dades i afecta clients andorrans amb reserves actives