Months after the cyberattack suffered by Booking.com, cybersecurity experts warn that the consequences are beginning to emerge in the middle of the holiday season. In April, the platform confirmed the hacking and unauthorized access to personal data and reservation details of some users, information that is now being used by criminal groups to commit targeted fraud.

According to industry experts, the real impact of a hack and leak usually arrives months later. With names, telephone numbers, emails and reservation data in their possession, cybercriminals can impersonate the hotel or the platform itself to request additional payments, modify information or generate incidents that the traveler discovers when they are about to travel or even upon arriving at their destination.

From hacking to problems during the holidays

«The difference with respect to other fraud campaigns is that with the hacking carried out, the criminal knows real details of the trip. Know where you are staying, when you are traveling and even the amount of the reservation. It is very difficult for the user to suspect that they are being the victim of a phishing attack,” explains Sergio García, manager of the technology company i3e.

The company warns that these scams can go beyond economic loss. In some cases, travelers find themselves with modified or canceled reservations or with discrepancies between the information they maintain and what appears at the establishment.

«The worst scenario is that the user discovers the problem upon arrival. After hours of travel you may find that your reservation does not appear, has been modified or there is no availability. In the middle of the high season, resolving a situation like this can be very complicated and expensive,” says García.

Added to this is the complexity of subsequent claims. When third parties intervene who have taken advantage of data obtained in a leak, determining responsibilities is not always easy and many affected parties are forced to assume additional accommodation or travel expenses while the incident is resolved.

How to avoid being left without a room and without money

Given the increase in these cases, specialists recommend verifying the status of the reservation directly with the accommodation a few days before the trip and distrust any communication that requests additional payments outside official channels.

«If we receive an email or message requesting an urgent transfer or updating bank details, we should be suspicious, even if it includes real information about our reservation. Direct verification with the hotel remains the best protection measure,” says García.

Experts also advise keeping proof of payment and reservation confirmations, as well as contacting the establishment again within 48 hours before the trip. «The leak has already occurred and the data is circulating. The important thing now is to prevent this information from becoming a fraud capable of ruining a vacation,” concludes the i3e manager.