Seems like a problem booking.com could instantly eliminate by enforcing 2FA for hoteliers.
The hotel gets "an" account for Booking. We now need to provide a 2FA credential that essentially needs to be accessed by any hotel front desk/office staff. What methods do we use for "many 2FA, one account"? (And then, how do all those second-factors get secured? Email accounts? Shared phones? Shared token? Shared Authenticator?).
It's probably bad enough the password's probably on a post-it under the front desk keyboard, but I don't think the average hotelier is going to be standing up something like Delinea Secret Server. ;)
I know it’s not gonna happen industry-wide. But this is how we do things everywhere I’ve worked for the past many years.