Phishing campaign impersonating Booking.com targeting UK hospitality

13 March 2025, 16:48

A woman using a laptop as she holds a bank card
Booking.com phishing scam. Picture: PA

Microsoft said the campaign was now posing a ‘tangible threat’ to UK-based hospitality and travel organisations.

A “rapidly evolving” phishing campaign that impersonates popular travel platform Booking.com is targeting hospitality organisations in the UK, Microsoft has warned.

Microsoft Threat Intelligence said cybercriminals had used a tactic – nicknamed “ClickFix” – to trick businesses into downloading and launching credential-stealing malware since December.

The attackers send convincing Booking.com-themed emails referencing guest reviews and account verification notices, enticing recipients to click through to a fake page that eventually enables cybercriminals to steal payment and personal data.

The theft can potentially lead to fraudulent transactions and reputational harm to the hotels and travel services.

Microsoft said the campaign was now posing a “tangible threat” to UK-based hospitality and travel organisations.

Phishing attacks are becoming more sophisticated

Sarah Armstrong-Smith, Microsoft UK

It urged businesses and consumers to contact the service provider directly if they received a suspicious email or message using contact forms listed on the official website.

Microsoft also urged firms to be wary of urgent calls to action or threats and to be cautious of email notifications that asked the recipient to click, call or open an attachment immediately.

Other tips to avoid falling victim include hovering over links to see the full URL and to search for typos, including within the body of the email, indicating that the sender is not a legitimate, professional source.

Sarah Armstrong-Smith, chief security adviser at Microsoft UK, said: “Phishing attacks are becoming more sophisticated, using advanced social engineering techniques like ClickFix to manipulate human behaviour and bypass traditional security measures.

“The recent campaign impersonating Booking.com is a clear example of how cybercriminals exploit trust and urgency to deceive individuals to gain access to sensitive information.

“Cybercriminals are constantly adapting their tactics, but by staying alert, questioning unexpected messages and behaviour, and enabling extra security measures, consumers can protect themselves against these evolving threats.”

Booking.com said: “Unfortunately phishing attacks by criminal organisations pose a significant threat to many industries. While we can confirm that Booking.com’s systems have not been breached, we are aware that unfortunately some of our accommodation partners and customers have been impacted by phishing attacks sent by professional criminals, with the criminal intent of taking over their local computer systems with malware.

“The actual numbers of accommodations affected by this scam are a small fraction of those on our platform and we continue to make significant investments to limit the impact on our customers and partners.

“We are also committed to proactively helping our accommodation partners and customers to stay protected.

“Should a customer have any concern about a payment message, we ask them to carefully check the payment policy details on their booking confirmation to be sure that the message is legitimate.

“Customers are also encouraged to report any suspicious messages to our 24/7 customer service team or by clicking on ‘report an issue’ which is included in the chat function.

“It is important to note that we would never ask a customer to share payment information via email, chat messages, text messages or phone.”

Earlier this week, Which? warned that a lack of effective checks was leaving Booking.com “wide open” to fraudsters, and called for the platform to do more to prevent fraud on its site ahead of the Online Safety Act illegal harms codes coming into effect later this month.

Booking.com was the most visited travel and tourism website worldwide in January, according to Statista.

But the Which? investigation found that an easily-hacked messaging system, failure to remove “scam” listings, and a lack of identity checks on property owners was leaving holidaymakers unnecessarily exposed on the site.

The consumer group was able to list a holiday home on Booking.com in less than 15 minutes and – unlike on Vrbo or Airbnb – Booking.com did not ask to see a driving licence or passport.

Which? said the lack of proper identity checks had led to a “deluge of dodgy listings” on the platform.

When Which? searched Booking.com reviews for the word “scam” in summer last year, if found hundreds of reviews complaining that they had paid for accommodation that did not exist.

The illegal harms codes of practice under the Online Safety Act will come into effect on March 17, requiring platforms to do more to prevent user-generated fraud on their sites by running risk assessments and having effective complaints procedures in place.

In addition, large platforms – those with seven million monthly active users in the UK – at medium or high risk of fraud will be required to have a dedicated channel to report any scams which slip through the net.

By Press Association

More Technology News

See more More Technology News

Sir Elton John performing

Elton John says ‘we will not back down’ in awards speech addressing AI concerns

Live
Customers purchase Nintendo Switch 2 at an electronics retailer in Tokyo on June 5, 2025.

Nintendo Switch 2 launch live: Where to buy, best deals, and early verdict

In this photo illustration, an Apple logo is seen displayed alongside the Google logo.

Tech giants Apple and Google 'profiting from phone thefts', MPs claim

A man's hands using a laptop keyboard

Scots warned of ‘scamdemic’ as £860,000 lost to cyber criminals in 12 months

A close up image of a The North Face fleece

North Face and Cartier customer data stolen in cyber attacks

Imagery of a Zilch payments card and a virtual card

Buy now pay later provider Zilch to launch first physical card

UK’s most EV-friendly city has been revealed by new research.

Cities with slowest EV charging times and least amount of chargers revealed

View of a VodafoneThree logo outside the firm's offices

Vodafone completes Three UK mega-merger to form ‘new force’ in mobile market

A hand holding a Monzo bank card and a mobile phone showing the Monzo app

Monzo annual profit surges as paying subscribers boost digital bank

Majestic British Airways Airbus A380 taking off from London Heathrow at sunset, amazing colors

UK airspace shake-up could slash journey times and cut flight delays for millions of passengers

File photo dated 30/05/25 of the saltmarsh at Abbotts Hall in Essex. Saltmarshes are 'significant' carbon stores, but are at risk from rising sea levels, new research reveals

UK's muddy saltmarshes vital to tackle climate change, report finds

Nigel Farage

Reform backs cryptocurrency tax cut as party receives first Bitcoin donations

Digital devices on office workplace table of young business woman

‘Young people and black workers at highest risk of workplace surveillance’

Debris from the Titan submersible, recovered from the ocean floor near the wreck of the Titanic, is unloaded from the ship Horizon Arctic at the Canadian Coast Guard pier in St. John's, Newfoundland, in June 2023

The shock household item discovered in 'sludge' of OceanGate sub wreckage

Google is facing a £25 billion legal claim in the UK, accusing the tech giant of abusing its dominant position in the online search advertising market

Google facing £25 billion legal claim over abuse of search advertising market

A hand holding a phone showing the Nvidia logo

Nvidia posts strong growth despite ongoing tariff challenges