They post bank account details for the customer to send a payment to.
Manually typing a link may not seem suspicious to many customers anyway.
Edit: Looks like the scam may involve credit/debit cards and links. The messages may be sent to customers via email, and the links are clickable that way. Not sure if that's an email client thing or if Booking.com makes them clickable in HTML.