Phishing wave following hotel bookings: Credit card data targeted

Fraudsters exploit genuine booking details to send convincing fake WhatsApp messages. Case numbers in Switzerland tripled in May.

Phishing wave following hotel bookings: Credit card data targeted

Deceptive WhatsApp messages following hotel bookings increase sharply

As news.joyn.at reports, the Swiss Federal Office of Cybersecurity (Bacs) is warning of an increasingly common fraud scheme in which criminals use existing hotel bookings as an entry point to obtain credit card data. In May, phishing reports in Switzerland tripled compared to the previous month: whilst eight cases were reported in April, there were already 23 in May – an increase that had not been recorded in 2024 and 2025 to date.

Bacs attributes the precision of the attacks to a data breach in the environment of the booking platform Booking.com, which became known in April. Criminals then gained access to sensitive user data and are now using it strategically to build trust through personalised messages.

The refund trick

In the first variant, hotel guests receive an unsolicited WhatsApp message that appears to come from the customer service of Booking.com or directly from the booked hotel. The criminals refer to actual past bookings and know both the name of the hotel and the names of the guests. The victims are told that an error occurred during the earlier booking and that they are now entitled to a refund.

To allegedly receive the money, recipients are asked to click on a link. This initially opens a fake but deceptively convincing website of the payment system Twint, which then forwards to a phishing page of a bank – where credit card data is to be entered.

Access to hotel systems

In the second variant, which according to Bacs has been known for longer, fraudsters first gain access to a hotel's booking systems via phishing or malware. With these access credentials, they can specifically view and contact open or upcoming guest bookings.

The affected guests are then often contacted directly via the platform's official messaging system or additionally by email or WhatsApp. The perpetrators deliberately use time pressure: they claim that the booking will be cancelled if a credit card verification is not carried out immediately via a provided link – or if an alleged advance payment is not made.

Regardless of the pretext used, the links sent always lead to deceptively designed phishing webpages on which credit card or bank details are to be harvested.

Recommendations from Bacs

Bacs states that "the utmost caution is currently required" and provides the following guidance:

Anyone who has already entered card details on such a page should immediately contact their own bank or credit card company to have the affected card blocked. If fraudsters have already stolen money, Bacs recommends filing a report with the police.

Source: Google News AT — Crime (de)

Read this article in the original language