Criminals are targeting the technology behind hotel bookings to get hold of real guest reservation data, then using that data to run convincing scams against travelers.
The most common patterns arrive by email, SMS, or WhatsApp, using your actual booking details to look legitimate, and usually ask you to "verify" a credit card or update a payment.
The single most reliable defense is to never act on the links or phone numbers inside an unexpected message. Contact the hotel or booking platform yourself, using details you already know are real.
If you've already handed over credit card details, call your bank immediately to freeze the card and dispute any charges.
A few days before your stay, a message arrives. It uses the hotel's real name, logo, colors, and imagery, addresses you by name, references your correct arrival date, quotes your actual room type, and sometimes even includes your real confirmation number. It asks you to confirm your credit card to secure a complimentary upgrade, or to update your payment because the original charge failed, or to complete a quick "verification" so your booking isn't canceled. Every detail matches what you remember about your trip. So you click.
That moment is the target of a fast-growing wave of hospitality-related fraud. Security researchers have documented multiple recent campaigns in which criminals compromised hotel and booking-platform accounts, pulled real guest reservation data, and used it to contact travelers by email and WhatsApp with fake payment requests. Booking.com and other major travel platforms have publicly acknowledged sharp rises in scam activity over the past year, driven in large part by generative AI tools that make convincing fake messages faster and cheaper to produce.
This article is written for travelers. It explains what's actually happening, the shape of the scams to watch for, and the one habit that stops nearly all of them. We recently published a companion guide for hotel operators on how properties can defend against these attacks. This piece is the traveler's version.
How your reservation data ends up in the wrong hands
The details a scammer needs to sound convincing (your name, arrival date, room type, and confirmation number) exist in more places than most travelers realize. Between the moment you book and the moment you check in, that information moves through your inbox, your device, the online travel agency you booked with, the hotel's own systems, and often several technology partners in between. A leak at any point along that path can put your booking in the hands of someone who intends to misuse it.
A few of the most common paths look like this.
Your own email inbox is one. Every booking confirmation you've received sits there, and if your email password gets exposed in an unrelated data breach, automated tools can quickly comb through those confirmations and identify exactly when and where you're staying. The same applies to your phone or laptop if it has been compromised by a malicious app, a suspicious browser extension, or a fake update.
Your OTA and loyalty accounts are another. Platforms like Booking.com, Expedia, Airbnb, and hotel loyalty programs hold detailed booking history. Password reuse across sites means a leak from any unrelated service can unlock those travel accounts.
The technology chain behind hotel bookings is a third. Modern hotels rely on a network of specialist systems: channel managers that push room inventory to OTAs, booking engines that power direct reservations, guest messaging platforms, and property management systems that stitch everything together. Any one of these can be targeted, and a compromise at a single provider can expose data across many properties at once.
And finally, the hotel's own accounts on OTA platforms are a well-documented target. Cybersecurity researchers at Sekoia recently documented a global campaign they named "I Paid Twice," after the subject line of an email from one of the defrauded travelers. In that operation, criminals compromised hotel systems, pulled real guest booking details, and contacted the guests by email and WhatsApp with fake payment requests. Some travelers paid twice for the same reservation, once to the hotel and once to the scammer.
The scams that show up in your inbox
Once your reservation details are in circulation, the shape of the scam is fairly consistent. A message arrives by email, SMS, WhatsApp, or phone, uses the hotel's real name, logo, and imagery, references your actual booking, and asks you to do something involving your credit card or your login credentials.
The specific pretexts vary, but a handful appear again and again.
1. The complimentary upgrade
The message congratulates you on being selected for a suite, an ocean view, or club-floor access. All you need to do to secure it is confirm your credit card, including CVV. Real hotels do sometimes offer upgrades, but an unsolicited upgrade offer that requires you to re-enter your full credit card details and CVV is almost always fraudulent. If in doubt, don't act on the message. Contact the hotel through a verified number to check.
2. The payment failure
You're told your original booking payment didn't go through, or your credit card has expired, and your reservation will be canceled within 24 hours unless you update it. If a real payment issue exists, it will appear inside the OTA or hotel platform where you actually booked. Check there.
3. The prepayment or deposit request
Especially common for resorts and higher-value stays. The property claims it needs a deposit before arrival, sometimes via wire transfer, gift cards, or cryptocurrency. A request to pay by gift card or cryptocurrency is almost always fraudulent. Wire transfers can occasionally be legitimate for group bookings, corporate accounts, or invoiced stays, but any unexpected transfer request, changed bank account, or new payment recipient should be verified directly with the property before you send money.
4. The online check-in
An invitation to complete check-in ahead of arrival, often bundling passport upload, ID verification, and credit card confirmation into one form. Legitimate hotels do send online check-in links by email and SMS, and those links may lead to an authorized third-party guest portal. But if the message is unexpected, or the details don't match your booking, don't act on the link. Open the hotel's app or website independently, or call the property, to confirm the request is real before entering any information.
5. The phone call from "the hotel."
Someone calls you a day or two before arrival. They know your name, dates, and room type, and read out a masked portion of your credit card as proof they have your file. Then they ask you to confirm the full number and CVV over the phone. A legitimate hotel will not ask for your full credit card number and CVV on an unexpected inbound call about a supposed problem. Hang up and call the hotel back on the number listed on their official website.
6. The SMS ("smishing")
A short text with a shortened link, asking you to verify your booking. The compressed format hides the suspicious details a longer email would expose. Treat any unsolicited SMS about a hotel booking with extra caution.
7. The WhatsApp message
Now one of the most common channels for these scams. The attacker impersonates the hotel's guest services team on WhatsApp, often with a matching profile photo, and asks you to complete a form or verify your reservation with a payment. Unless you specifically arranged WhatsApp contact with the hotel through their official channel, any WhatsApp outreach about your booking should be assumed fraudulent until proven otherwise.
8. The confirmation for a stay you never booked
Occasionally the pattern inverts. You receive a booking confirmation for a hotel you never reserved, with a "click here to cancel" button. The cancel link is the trap. Instead, open the booking platform's app or website independently and check your account. If a reservation you didn't make appears there, contact the platform and secure your account.
Real messages versus fake ones: the tells
Even the most polished phishing attempt tends to leave a few consistent tells behind.
The sender's actual email address rarely matches the hotel's real domain, even when the display name is styled to look legitimate. A message from "The Grand Hotel Reservations" might arrive from reservations@grand-hotel-support.example, or from something like no-reply@grandh0tel.example with a zero in place of the letter o. The domain is where the truth lives, not the friendly name.
Hover over any link on a computer, or long-press it on a phone, and the real destination appears. If it points anywhere other than the hotel's actual website, it's not safe to tap. This one check catches most phishing attempts on its own.
Urgency is another consistent marker. "Within 24 hours." "Immediately." "Your reservation will be canceled." Real hotels almost never communicate this way. Urgency is precisely what a scammer wants, because it stops you from stopping to think.
The payment channel is a giveaway too. If you booked through Booking.com, Expedia, or another OTA, check your original confirmation to see how payment is meant to happen. If a message asks you to pay in a way that doesn't match those terms (a different platform, a new account, or an unexpected method), treat it as almost certainly fraudulent.
And finally there's the internal voice that says something feels off. That voice is nearly always right, and it costs nothing to pause and verify.
The one habit that beats nearly all of these scams
If there's a single thing worth taking from this article, it's this.
Never act on the link, phone number, or contact method inside an unexpected message. Always reach out to the hotel or booking platform yourself, using contact details you already know are legitimate.
That means the phone number on the hotel's official website, which you typed into your browser yourself. The email address on your original booking confirmation. The OTA app you booked through. A phone number you've dialed before and know is real.
Every scam pattern described in this article depends on you using the contact method the scammer supplied. Route around it, reach the hotel through a channel you already trust, and the scam collapses. This one habit, applied consistently, works against emails, SMS, WhatsApp messages, and phone calls alike.
What to do if you've already handed over credit card details
Move quickly. Acting in the first hour makes a real difference.
Call your bank or credit card issuer immediately, using the number printed on the back of your credit card. Ask them to freeze the card, issue a new one, and dispute any charges you don't recognize. Most banks can lock a compromised card within minutes.
Change your password on any account where you used the same or a similar one, particularly your email, your hotel loyalty accounts, and any OTA logins. If you're not already using a password manager, this is a good moment to start.
Be alert for follow-on scams. Once your details are circulating, you may receive calls from someone claiming to be your bank's fraud team, asking you to confirm information or move money to a "safe" account. This may be the same criminals coming back for a second attempt, or a related group that acquired the compromised details. Either way, never confirm anything on an inbound call. Hang up and call your bank back on the number on your credit card.
Now verify the hotel you booked with. They may not know their guest data is being used this way, and letting them know helps protect the next traveler in line.
{{pms-four}}
A closing thought for guests
The scams described in this article work because they don't feel like scams. They arrive exactly when you're expecting to hear from the hotel, with exactly the information a real hotel would have. That's what makes them dangerous, and it's also what makes the defense simple.
Trust the hotel. Distrust the message.
If you want to know whether something is real, don't reply to the email, don't tap the link, and don't call the number it gave you. Go to the hotel's real website, call the number listed there, and ask them directly. Two minutes of independent verification is the most reliable travel safety habit there is.
Safe travels.
roommaster is the unified hospitality platform trusted by thousands of independent hotels worldwide. If you're a hotelier looking to strengthen the security and guest experience at your property, book a demo.
Mayela Lozano is a content strategist with a passion for hospitality and technology. She collaborates with roommaster on content creation, highlighting how technology can streamline hotel operations and enhance guest satisfaction. When she’s not creating content, Mayela loves to travel and spend time with her two little ones, discovering new adventures and making memories along the way.
Join Thousands of Hotels Thriving with roommaster
The transition to roommaster is straightforward and efficient. Our implementation team handles data migration including reservations, guest profiles, and historical information.
The transition to roommaster is straightforward and efficient. Our implementation team handles data migration including reservations, guest profiles, and historical information.
Hotel's Competitive Set (Compset): Hoteliers Guide 2026
August 23, 2026
Hospitality Technology
What Is A Timeshare? Types, Costs, And How Ownership Works
August 23, 2026
Hospitality Technology
Hotel Minibar Management Software: Complete Buyer's Guide 2026
August 20, 2026
General
Hospitality Technology
Hotel Phone System: Complete Buyer's Guide 2026
August 20, 2026
Hospitality Technology
Online Bookings
10 Best Cabin Rental Reservation Software For 2026
August 17, 2026
Hotel Management
Data Management
Booking Pace: What It Means and How to Track It
August 5, 2026
Hotel Management
Data Management
Hotel Renovation: How to Budget, Fund, and Protect Revenue
August 4, 2026
Data Management
Hotel PMS
What Is USALI? The Uniform System of Accounts for Hotels Explained
August 4, 2026
Hotel Management
Data Management
Hotel Asset Management: A Practical Guide for Independent Owners
August 4, 2026
Hotel Management
Data Management
Hospitality Financial Management: An Owner's Guide
August 4, 2026
Join Thousands of Hotels Thriving with roommaster
See how roommaster's unified platform can work for your property. Our team will walk you through features tailored to your specific needs and operations.