Booking.com users angry at firm's response to hacks
bbc.com
bbc.com
> The company, which is one of the biggest hotel and holiday websites in the world, has not itself been hacked.
>
> Instead, criminals have tricked their way into the administration portals of individual hotels that use the service.
>
> This enables them to send messages and fool customers into paying them instead of the hotel.
Previous headlines from the BBC have been even worse:
- Booking.com users angry at firm's response to hacks
- Booking.com hackers increase attacks on customers
How is this not libel?
Genuinely: What do people here think that are Booking.com supposed to be doing about this? Any sophisticated phishing group aren't going to be making rookie errors like hotlinking images when they set-up a phishing siter impersonating Booking.com. They're already doing DKIM signing, DMARC and SPF.
It's unclear to me if the phishing groups are sending emails out directly using the stolen personal details, or using some sort of in-app messaging functionality. If it's the latter I don't think booking.com even supports linking URLs in messages sent out via this mechanism.
Nothing in the report or what you have quoted is misleading.
Any reasonable person would read this headline and assume Booking.com's platform had been hacked.
> Criminals then send a Google Drive link to the staff saying that it contains an image of the passport. Instead the link downloads malware on to staff computers and automatically searches the hotel computers for Booking.com access.
How would 2FA stop this?
https://www.theguardian.com/money/2023/oct/23/bookingcom-cus...
Not having a messaging system that lends authority to messages if they aren't able to secure it (including assuring that partners with access secure their ends) adequately for the appearance of authority that is created.
They post bank account details for the customer to send a payment to.
Manually typing a link may not seem suspicious to many customers anyway.
Edit: Looks like the scam may involve credit/debit cards and links. The messages may be sent to customers via email, and the links are clickable that way. Not sure if that's an email client thing or if Booking.com makes them clickable in HTML.
This is even less credible to me than a phishing site set-up to take card details. As soon as you try to make a payment to a scammer's bank account, confirmation of payee will fail because the bank details won't match the hotel's. It should also raise alarm bells because it's a completely out-of-character thing to be asked to do prior to a stay with a hotel.
I must say it's a clever approach; generally poor English in messages is a red flag for scams, but you tend to forgive that when you know it's coming from a hotel in another country.
Not pretending it's not their problem, as a start
Because it absolutely is
Then, work with hotels so that communications from them are authenticated in some way
Are you sure? This makes it sound like whatever account hackers gained control of was able to send messages directly to the app. If they log into a booking.com portal to do that, and booking.com hasn't set up multifactor authentication, they aren't blameless.
The use dark patterns all over their website to their customers and pressure hotels in accepting lower rates or be defacto blacklisted. Another middleman we don't need nor want.
What alternatives are people using?
That said I've stayed in some really downtrodden "hotels" I'd booked on booking.com that looked OK in photos but were not up to scratch in reality.
Book online directly. The hotels hate OTAs (Online Travel Agents). You can typically find better terms direct on the hotel website (e.g. breakfast included or more flexible cancellation).
If you are in a financial position where you need to watch every penny, then take the extra time and effort to book by phone or email, because in some jurisdictions the hotels have rate-parity clause which means the hotels can't advertise a lower rate on their website than you can find on the OTA website. This probably mostly applies in North America, this sort of thing is likely illegal (or verging on ) in Europe so you're unlikely to get a better deal than a European hotel offers on its website already.
If you like the big US chain hotels (Hilton, Marriott etc.) and you travel reasonably frequently then pony up for an AMEX premium-tier card which gets you access to AMEX rates, and also some perks (e.g. premium WiFi for free, late-checkout etc.).
They will have gone through security on their bank's app or website, which will have warned them about common scams like this and told them to check that what they are doing is legitimate.
https://www.psr.org.uk/our-work/app-scams/
I am assuming this is an "Approved Push Payment" scam where people are transferring money from their bank account directly to the fraudster, rather than by using a credit or debit card. If the payments were by card then a chargeback should be easy to file.
Booking.com says the hotel is at fault for having their credentials leaked; the hotel says booking.com failed to protect their account, the bank says the user was phished so it’s not their fault.
IMO if booking.com offers a messaging service which lends far more authority than “just a random person SMSing you” then they’re on the hook for this.