
Booking.com has confirmed a major cyber incident after 'unauthorised' third parties accessed the sensitive reservation details of millions of customers.
The breach, detected on 13 April 2026, has seen hackers harvest names, email addresses, phone numbers, and physical addresses from Booking.com systems. While the company maintains that financial data was not compromised, cybersecurity experts warn that the exposed, compromised booking details are being used to fuel a global wave of 'reservation hijacking' scams. These attacks use the stolen context of a real holiday to trick travellers into making fraudulent payments through official-looking channels.