No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

This New Hotel Reservation Scam Is Fooling People Who Use Sites Like Booking.com

November 15, 2025
in Protection
0
This New Hotel Reservation Scam Is Fooling People Who Use Sites Like Booking.com



If you’ve booked a hotel through a platform like Booking.com or Expedia, beware any communication that directs you to confirm your payment details to hold your reservation. Threat actors are targeting the hospitality industry with a phishing campaign designed to steal from travelers.

As outlined by security firm Sekoia.io and reported by The Hacker News, the scheme is referred to as “I Paid Twice” because hotel customers are eventually conned into handing over their banking information. Scammers contact guests via WhatsApp or email about their booking, saying that they need to verify their payment or risk cancellation. The link goes to a fake landing page that looks like Booking.com or Expedia, where victims are prompted to provide card information.

This isn’t the first scam to target Booking.com: Scammers have previously spoofed the site to spread malware directly to users via both fake CAPTCHAs and homograph attacks, which exploit similar characters in the URL to redirect to a malicious website.

This multi-step campaign actually begins when hackers target hotels themselves with ClickFix attacks, a type of social engineering attack designed to trick users into downloading malware via fake error messages or CAPTCHA forms. (I’ve covered a handful of ClickFix schemes, such as those spread via AI-generated instructional videos on TikTok and expired invite links on Discord.)

The scam runs as follows: Hotel managers receive emails from compromised accounts with phishing links that redirect to a supposed reCAPTCHA page. This is the ClickFix component, as targets are instructed to complete the challenge to “ensure the security of your connection.” A couple of redirects lead to the user copy and execute a PowerShell command that downloads a Remote Access Trojan (like PureRAT) to their device.


What do you think so far?

Once the malware has been delivered, it allows threat actors remote access, including control of the mouse and keyboard, data exfiltration, command execution, file uploads and downloads, keylogging, and webcam and microphone capture. Hackers are then able to steal admin credentials to gain access to booking platforms and send the aforementioned phishing emails to hotel guests—or they can sell the information to other cybercriminals.

Don’t fall for the hotel booking scam

You can’t control whether a hotel manager unwittingly hands over access to your booking information. But you can avoid further compromising your personal and financial data by staying vigilant to any unexpected communication about your reservation. A reputable hotel probably won’t contact you via a booking platform (nor will the platform itself) to demand payment for holding a reservation you’ve already confirmed.

This sense of urgency is meant to trick you into acting quickly, so if you’re not sure what’s going on, call the hotel directly using the number on their official website (not from the email or WhatsApp message). Don’t click any links, and don’t enter any information unless you have confirmed that you are on a legitimate booking platform or hotel website.



Editorial Team

Editorial Team

Related Posts

You Can Get These New Sony Noise-Canceling Earbuds on Sale for $65 Right Now
Protection

You Can Get These New Sony Noise-Canceling Earbuds on Sale for $65 Right Now

April 23, 2026
This Eufy Home Security Bundle Is $400 Off Right Now
Protection

This Eufy Home Security Bundle Is $400 Off Right Now

April 23, 2026
This Massive QLED TV Drops to Its Lowest Price
Protection

This Massive QLED TV Drops to Its Lowest Price

April 23, 2026
10 Hacks Every Brave Browser User Should Know
Protection

10 Hacks Every Brave Browser User Should Know

April 22, 2026
10 Hacks Every Android Auto User Should Know
Protection

10 Hacks Every Android Auto User Should Know

April 22, 2026
Did Apple Just Fix the iPhone Bug That Let the FBI Recover Deleted Signal Messages?
Protection

Did Apple Just Fix the iPhone Bug That Let the FBI Recover Deleted Signal Messages?

April 22, 2026
Load More
Next Post
Client Challenge

Client Challenge

Popular News

  • BlackRock buys $900M in Bitcoin via iShares Bitcoin Trust

    BlackRock buys $900M in Bitcoin via iShares Bitcoin Trust

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Use the ‘One-Touch’ Rule to Manage Your Inbox

    0 shares
    Share 0 Tweet 0
  • Contrary To Popular Belief, This Is Not The Worst Bitcoin Crash In History – Here’s The List

    0 shares
    Share 0 Tweet 0
  • Expert Predicts What Will Happen To Bitcoin Price Amid The Miner Shift To AI

    0 shares
    Share 0 Tweet 0

Latest News

Cardano Gets Filecoin-Backed Storage Upgrade

Cardano Gets Filecoin-Backed Storage Upgrade

April 23, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure A new storage offering is moving from...

Lululemon is getting a Nike veteran as its new CEO. An analyst says that could be a problem.

Lululemon is getting a Nike veteran as its new CEO. An analyst says that could be a problem.

April 23, 2026
0

Yoga-wear maker Lululemon on Wednesday said its board had approved Nike veteran Heidi O’Neill as its new CEO. But analysts...

New York, Illinois Ban Officials From Prediction Markets

New York, Illinois Ban Officials From Prediction Markets

April 23, 2026
0

New York Governor Kathy Hochul has signed an executive order banning state employees from betting on prediction markets, following a...

PACL - Career Advisor - HigherEdJobs

PACL – Career Advisor – HigherEdJobs

April 23, 2026
0

Location: Multiple CampusesJob Type: Admin, Temp, Full TimeJob Number: 002609Department: 5435 DCWIB Adult Trng Assessm't Prg FY21Opening...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.