Drooid Logo
Back to story perspectives

Full Breakdown

Phishing Attack Generates Thousands of Fake Bookings on Booking.com

By Drooid · · How we work

Core Event

A sophisticated phishing attack in August gave cyber criminals temporary unauthorized access to the Booking.com account of Life’s 2 Short, a small Exeter-based property-management firm run by 46-year-old Victoria Pollard. The breach allowed thousands of fictitious reservations to be listed under the company’s name, prompting overseas travelers to arrive at non-existent properties.

Impact on the Business

Pollard, whose firm employs only one other staff member, described herself as “devastated and exhausted.” The attack also blocked Pollard’s access to her accounts, causing genuine reservations to be missed.

Booking.com Response

Booking.com issued an apology and said it was providing “full support” to the affected partner. The platform removed all impacted listings and offered customers “relocations, refunds or free cancellations.” The company’s investigation concluded that the accommodation was likely the victim of a sophisticated phishing attack by cyber criminals, which compromised the partner’s computer systems and led to temporary unauthorized account access. “Our investigation indicates the accommodation was likely the victim of a sophisticated phishing attack by cyber criminals, which affected their own computer systems and led to temporary unauthorised access to the accommodation partner's Booking.com account.” — Booking.com. Victoria Pollard

Verbatim Quotes

  • “Our investigation indicates the accommodation was likely the victim of a sophisticated phishing attack by cyber criminals, which affected their own computer systems and led to temporary unauthorised access to the accommodation partner's Booking.com account.” — Booking.com

The incident highlights the vulnerability of small hospitality operators to cyber threats and underscores the importance of robust security measures for online booking platforms.