They post bank account details for the customer to send a payment to.
Manually typing a link may not seem suspicious to many customers anyway.
Edit: Looks like the scam may involve credit/debit cards and links. The messages may be sent to customers via email, and the links are clickable that way. Not sure if that's an email client thing or if Booking.com makes them clickable in HTML.
This is even less credible to me than a phishing site set-up to take card details. As soon as you try to make a payment to a scammer's bank account, confirmation of payee will fail because the bank details won't match the hotel's. It should also raise alarm bells because it's a completely out-of-character thing to be asked to do prior to a stay with a hotel.
I must say it's a clever approach; generally poor English in messages is a red flag for scams, but you tend to forgive that when you know it's coming from a hotel in another country.