Site icon TheCyberThrone

Booking.com Confirms Data Breach

Advertisements

On April 13, 2026, Booking.com confirmed that unauthorized third parties accessed customer booking information. The company began notifying affected users via email on Sunday evening, stating it had detected “suspicious activity” affecting “a number of reservations.”

What Data Was Exposed

According to Booking.com’s customer notification, the potentially compromised data includes:

What Remains Unknown

Booking.com has not disclosed:

The company stated the situation is “now under control” but provided no technical details about containment or evidence collection.

Prior Incident History

This is not Booking.com’s first breach. In 2018, unauthorized access via phishing compromised booking data for over 4,000 customers in the United Arab Emirates. Booking.com reported this incident to Dutch authorities 22 days after discovery, exceeding the GDPR’s 72-hour notification requirement. The company was fined €475,000 by Dutch regulators.

Customer Guidance from Booking.com

The company advised affected customers to:

Exit mobile version