Booking.com Scam UK: Spot a Fake Payment Message
A message inside a genuine booking platform can still be fraudulent; compare every payment request with the policy in the original confirmation.
What the scam looks like
A message refers to a real reservation and claims that payment failed or that card details must be re-entered to avoid cancellation. It may arrive by email, phone, text, WhatsApp or a booking-platform message, and it may contain convincing dates, prices and property details. The link leads away from the expected payment journey or the requested transfer differs from the booking confirmation.
Do not assume how the data was obtained
A fraudulent message can appear in a genuine thread if an account used to send it has been compromised. Other data exposures or impersonation methods are possible. A single suspicious message does not prove that Booking.com's central systems were breached, nor does it prove that they were not. The useful fact is that a message appearing in a genuine thread is not sufficient authentication.
Booking.com's published advice
Booking.com says it will not ask travellers to share credit-card details by email, phone, text or WhatsApp, and will not ask for a bank transfer that differs from the payment-policy details in the booking confirmation. It also says Customer Service should ask only for a reservation ID and/or PIN, not an account password or sensitive financial information.
Do not extend that statement into the unsupported absolute that every in-app request concerning a card is automatically fraudulent. Instead, compare the request with the booking terms and confirm it through official Customer Service before taking action.
Warning signs
- A new payment or card request conflicts with the confirmation.
- The message creates a 24-hour or similarly urgent cancellation threat.
- A link leaves the expected Booking.com payment journey.
- The property asks for a bank transfer or payment method not stated in the booking policy.
- Someone claiming to be Customer Service asks for the account password or full card number.
Check the request safely
Do not use the link. Open the Booking.com app or site independently, review the confirmation and contact Customer Service through the official account. If the property appears to have sent the message, ask Booking.com to investigate the account rather than relying only on a reply in the same thread.
If card or login details were entered
Contact the card issuer immediately, change the Booking.com password and any reused password, and report the incident through official Customer Service. Keep screenshots, the URL and the booking confirmation.
Reporting in the UK
Forward suspicious emails to report@phishing.gov.uk and texts to 7726. If money was lost or an account was compromised, report the crime to Report Fraud at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland; in Scotland, call Police Scotland on 101.
Frequently asked questions
Does a message in the Booking.com app prove it is genuine?
No. Compromised provider accounts can be used to send messages through genuine systems. Verify the request against the confirmation and with Customer Service.
Does the message prove Booking.com itself was hacked?
No conclusion about the point of compromise can be drawn from the message alone.