Booking.com hackers increase attacks on customers
bbc.co.uk
bbc.co.uk
I re-booked with the hotel directly through their site (small independently owned hotel in a ski town). The whole process felt _shady_ but also it seems like the owner couldn't find a way to get their Booking.com listing removed. I am regretting not using a virtual card number for the initial booking through Booking.com.
Had a place triple charge me, place ignored all CS attempts from me. Privacy refused to help basically saying all three must have been valid and "they have policies with banks" that meant they "couldn't chargeback".
Or someone who uses Amazon at all, because they don't actually charge your card when you make a purchase, they charge it randomly about 6 hours later. This trips me up all the time.
Yes they will. I tried to buy a VPS from OVH, and then they immediately locked my account, demanded ID, and refused to refund. Contacted Privacy support to file a chargeback, and they just gave me an equivalent amount of Privacy credit and said not to worry about it, since an actual chargeback would be far more inconvenient for me.
How large was the fraudulent charge?
capital one supports it. Amex too.
(I'm leading a very nomadic lifestyle and I've used Booking over 50 times)
Also maybe do not provide card info "for card confirmation". It literally gets just sent to the place in the clear. Many of them print it and keep for who knows how long for anyone to see.
I could be wrong but I don't believe I was given the option not to. I was unaware it was sent in the clear until now.
Nowadays they send a virtual card that has been generated by booking.com to the hotel. The card details of the guest stay with booking.com
Do you know what region/hotels are actually affected by this?
Found this article from last month about places still waiting for their money with no signs of when or if it might come.
https://www.theguardian.com/travel/2023/nov/10/booking-com-t...
"Aw, shucks, the payment system is still broke. Just be a few months before the repair company can be by to fix it. Nothing to worry about here. No need to contact a lawyer or the AG's office." ?
What you have here is commission fraud on behalf of the hotel against Booking.com, and if you call back Booking.com and tell them about it, they will set the hotel straight.
Or you get back to the hotel, tell them you understand how commission fraud works and if they are willing to split that commission (18%) half and half with you.
Maybe booking.com sends an email to the hotel, but they legitimately don't have the login credentials to cancel the reservation?
This case was commission fraud by the hotel against booking.com
That sure sounds like a crime in itself, no?
You don’t. You cancel on Booking.com and then pay the hotel 90% of what Booking quoted.
https://www.theguardian.com/business/2023/oct/01/booking-com...
Having been scammed by booking.com car rentals myself, I see no surprises there.
> an Australian running a two-bedroom villa in Bali [--] managed to get paid out last week for the A$11,000 she was owed since March by tracking down a finance officer on Facebook.
Then again: these 'new middlemen' are all equally shady themselves.
I've done this many times (not exactly the same, see below) with AirBnB and Redweek rentals -- once you get to know the property owner by staying there once or twice through Redweek they will happily agree to a better rate to deal direct.
Is it fraud? Sounds like bog-standard disintermediation.
I'm pretty sure it's the first time, in over 20 years of using the internet, that I've fallen for a phishing scam.
It completely gets through your defences because the message is sent via the Booking.com app and is about a legit hotel booking you've made. Very nasty.
But very poor of Booking.com to not be better at detecting these messages. The first consumer reports I can find about this scam go back to January [1], and it shouldn't need very sophisticated text classification to recognise and block them.
More details about the scam here [2].
[1] https://insideflyer.co.uk/2023/01/beware-of-this-booking-com...
[2] https://perception-point.io/blog/booking-com-customers-hit-b...
Had a trip booked to Japan, multiple hotels reserved with booking and Agoda.
At some point I received one of those messages, which arrived directly through Booking's system. As mentioned in the article it's not even though SMS -- technically it did come to my email but just as an email copy of the message from their system.
The oddest thing was that a couple days later I got a follow-up message with a profile icon matching the hotel, but a message written as if from a customer, and they said something about trying the spam link, putting their CC info in, and nothing happening.
I wasn't sure if that was the scammer trying to impersonate a customer or if somehow another customer was attached to my message thread.
If the latter, I'd surmise that Booking's message underlying system is email and somehow when the scam was sent out, it was done with cc or bcc to a set of customers rather than only me.
If the former, it doesn't really make sense to act like it didn't work otherwise the targeted customer is less likely to try it.
So odd.
The MO is the same as described in the article -- a well-crafted email with a link to a file in a respected cloud host.
Is there a centralized place (FBI ?) to report these attacks? The bad actors will be obvious in aggregate.
How does clicking a link install and run an executable?
[1] https://partner.booking.com/en-us/help/policies-payments/gue...
If they wouldn't send the card information 'in plain text' it would be useless to the hotel. And every time you visit a hotel and hand them your card they tend to make an imprint of the card, the only thing the hotel doesn't have is the CVC and in the normal flow this isn't exposed, only when you escalate to some level of exception (and I'm not sure what the criteria are for that).
Those of us who transact directly with the hotel instead of booking agents stay winning I guess.
Third-party aggregators and hotels are a complete shit-show. But as long as I can save $30 on my trip, I will keep using them...
The real solution is for the credit card companies to lay down requirements for these merchants (no storing in plain text).
The CVC is just slightly less problematic than the rest of the card data.
And that small hotel in Tyrol is probably ok, but I had my card cloned within minutes of eating at a restaurant in Toronto. The whole concept of a bunch of numbers that allow for arbitrary charges against you is flawed.
Booking.com doesn't facilitate fraud any more than your credit card company does, and so far I've been able to successfully dispute every charge that I did not agree with on my card. The day that changes I'll stop using them entirely.
I haven't had my card imprinted (or, later, photocopied) in hotels since a long time. Now it's just a pre-authorization.
Although recently I had my credit card photocopied by a car rental agency so they would be able to phone the card processor and cancel the pre-auth manually. Absolute madness.
> the only thing the hotel doesn't have is the CVC
Considering the most recent credit cards that I have been issued, most lost the embossing and now print the PAN on the back together with the CVC, so if some hotel photocopies the card - as nobody have the imprinters anymore - the CVC is there. This also applies to the last embossed card that I have in my wallet, an Amex card, which always had the CVC on the front that wasn't captured with an imprinter. Now with photocopiers, it is.
How else could it work?
1. Booking request made, Booking.com holds card details
2. Hotel requests payment
3. Booking.com makes transaction from your card to hotel
B)
1) Booking request made
2) Booking.com requires card details for immediate payment to them
3) Booking.com sends money from their account to hotel
C)
1) Booking request made, Booking.com requires guest identity only
2) Hotel takes payment on arrival
The charge comes from Booking itself and I assume they ten transfer the money to the hotel/etc
Charge came from Panama (the country) and the hotel isn't anywhere near.
No physical card or further verification.
However, I think the integrations and payment terms with the major hotel brands have gotten good enough that Expedia now prefers to be paid a commission by the hotel. This benefits Expedia as they are no longer wasting money dealing with chargebacks and card processing fees.
FYI, typically, a hotel franchisee will pay 10% to 15% to the hotel brand franchisor (Hilton/marriott/etc), and if the guest uses a travel agent like Expedia or Booking or any of the corporate travel ones, another 15% or more to the travel agent, and then the 3% to the payment processors. So for a guest who reserved via travel agent at a franchised hotel, ~30% of the room rate right off the top will not make it to the hotel itself.
And that is excluding the typical 10% to 20% sales tax the guest pays the government on top of the room rate!
Depending on the jurisdiction, if credit card commissions are high and the vendor/hotel aren’t setup for bank transfers, this avoids paying 2x Amex/mastercard/visa commissions.
https://arstechnica.com/information-technology/2023/02/myste...
Generally, though, more and more hotels shifted from faxes to API integrations via channel managers. But that's a whole extra step in sophistication.
Good times!
https://partner.booking.com/en-us/help/policies-payments/pay...
The fact that it stores your card is pretty much an unescapable reality. Just like car rentals, they reserve the right to charge you before, during or after your stay, for the booking or for damages.
Too bad that those are not so popular and only few banks activate the service (I believe it's handled by Visa or Mastercard).
Why the hell don't banks get their shit in order? And why am I paying an X% commission for that crap?
The hotel gets "an" account for Booking. We now need to provide a 2FA credential that essentially needs to be accessed by any hotel front desk/office staff. What methods do we use for "many 2FA, one account"? (And then, how do all those second-factors get secured? Email accounts? Shared phones? Shared token? Shared Authenticator?).
It's probably bad enough the password's probably on a post-it under the front desk keyboard, but I don't think the average hotelier is going to be standing up something like Delinea Secret Server. ;)
I know it’s not gonna happen industry-wide. But this is how we do things everywhere I’ve worked for the past many years.
https://HiChee.com lets hosts "verify" their listings to offer book direct pricing. Plus, guests can pick which platform has the lowest price for a chosen rental.
I call BS. It's Booking.com's responsibility to ensure that the people logging into their portal are the actual hoteliers. Time to mandate 2FA.
They will do nothing except of refund if you are scammed by hotel with false advertising.