Watching Out for Scams

scams

Picture it: guests are so excited for their trip. They book a hotel. Everything looks normal.

Then a message comes in that seems routine, like a standard follow-up message from guest services. It references the trip, including the hotel name, travel dates, and payment details. It seems legit, but it’s not. 

This is part of a growing scam trend that threat researchers at Gen (the company behind Norton) call the Reservation Hijack scam. It’s so effective because it leverages confidential details that only you and the hotel you booked with should know.  

In April 2026, Booking.com, a major online travel booking platform, warned that unauthorised parties had accessed some customers’ booking information, including names, contact details, and reservation data, according to reporting on the breach by The Guardian. The number of customers affected was not disclosed. Incidents like this can give attackers the context they need to launch Reservation Hijacking scams.

What is a Reservation Hijack scam?

A Reservation Hijack scam is a type of targeted phishing scam that uses real hotel reservation booking details to make messages feel legitimate, tricking travellers into sharing payment details or sensitive information. 

In advanced cases, scammers gain access to hotel systems or booking platforms like Booking.com, allowing them to contact guests through channels that are normally considered trustworthy and secure. That means the message you receive might not only look real, but also come through a platform you trust, making the scam significantly harder to detect. That’s what makes this scam so effective. It doesn’t ask you to trust an unfamiliar-looking message. It asks you to trust a message that already looks and feels very familiar.

What Norton researchers uncovered

Norton researchers have observed an increase in the number of scams that exploit real booking data and trusted travel platforms.

Key findings include:

  • Scammers are increasingly targeting travellers with active reservations, not random users.
  • Messages are delivered through trusted channels, including booking platforms and official-looking emails.
  • Attacks frequently involve urgent payment requests tied to legitimate bookings.
  • The use of real reservation details makes these scams significantly more effective than traditional phishing scams.

The emergence of Reservation Hijack scams reflects a broader trend: scammers are moving away from generic messages toward highly contextual, personalised attacks.

How scammers get access to reservation details

One of the most unsettling parts of this scam is how much attackers seem to know. In some cases, scammers gain access to reservation details by:

  • Compromising hotel or partner accounts by targeting hotel staff with phishing attacks or exploiting weak passwords.
  • Exploiting third-party vendors connected to booking systems
  • Accessing platform messaging tools to impersonate legitimate properties

If guests are targeted by one of these scams, it doesn’t necessarily mean a personal account was hacked. In some cases, a company that holds data may have suffered a breach, exposing real customer information that attackers can use to make their messages appear more legitimate.

How the scam unfolds

A Reservation Hijack scam often starts with a message related to a travel booking you recently made. It could arrive via email, SMS, WhatsApp, or even through a booking platform’s messaging system. Because it references real details, it doesn’t immediately raise suspicion.

The message typically introduces a problem, such as an issue with guests’ payment or a need to verify the reservation. There’s often a sense of urgency, suggesting that the booking could be cancelled if guests don’t act quickly.

From there, guests are directed to a payment page that appears legitimate but is actually designed to capture financial or personal information. By the time guests reach this step, the context feels so real that many people don’t think to question it.

Why this scam is so convincing

What sets this scam apart is how personal it feels. Instead of guessing, attackers may already know where guests are travelling, which hotel they booked, and how long they’re staying.

That context creates a powerful sense of trust. The message doesn’t feel random or out of place. It feels like part of the typical travel experience. And that’s exactly the point. 

Scammers are no longer just trying to trick guests with poorly written emails. They’re using real information and real moments in everyday life to make their requests feel completely reasonable.

What scammers can do with the information

Falling for a Reservation Hijack scam can lead to more than just a single fraudulent charge.

Depending on what information is shared, scammers may make unauthorised purchases using payment details, steal personal information for identity theft, attempt additional scams using data, or disrupt travel plans if the booking is affected.

The impact can extend beyond the guest’s trip, especially if sensitive information is compromised.

More news here.