Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: Two different problems are often described as a “Booking.com hack.” Salt Security disclosed Facebook OAuth implementation flaws on 2 March 2023 that could have enabled traveler-account session hijacking; Booking.com said it remediated them and no exploitation was known at disclosure. Separately, criminals have repeatedly phished hotel and accommodation-provider staff, then used those accounts to target guests and move money. Action Fraud assessed its reported cases as attacks on providers rather than Booking.com’s backend infrastructure.

There are two documented account-takeover paths

Scenario Victim Initial access Likely objectives Primary control layer
Facebook OAuth flaw disclosed 2 March 2023 Booking.com user accounts Manipulation of the social-login OAuth flow Session hijacking, personal-data theft, booking or cancellation Platform remediation and stronger OAuth design
Provider phishing campaigns, including Storm-1865 Hotel and accommodation staff Phishing, fake CAPTCHA/ClickFix pages and credential-stealing malware Extranet control, guest-data access and fraudulent transactions MFA, staff training, endpoint security and independent verification

These paths have different victims and defenses. A suspicious message from a property does not, by itself, prove that Booking.com’s central systems were breached.

What the 2023 Facebook OAuth vulnerability could do

Salt Security reported flaws in Booking.com’s Facebook OAuth social-login implementation on 2 March 2023. The problems could let an attacker manipulate OAuth steps, hijack an authenticated session, extract personal information, and use the account to make or cancel reservations.

Booking.com’s developer documentation confirms that OAuth 2.0 is used in its Accounts Portal authentication flow. That establishes the relevant technology, but not that every OAuth deployment was vulnerable or that customer accounts were actually compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Booking.com remediated the reported issues. Salt reported no evidence that the flaws had been exploited in the wild at the time of disclosure. That is a time-qualified finding, not a guarantee that later phishing campaigns were impossible.

How criminals took over accommodation-provider accounts

Phishing aimed at hotel staff

Booking.com describes partner account takeover as “Frequently a result of phishing,” involving unauthorized access to an accommodation provider’s extranet account. A stolen provider account can expose guest details and enable fraudulent transactions.

Rank #2
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Action Fraud recorded 532 reports and £370,000 lost during its June 2023–September 2024 reporting period. Its assessment was that the specific takeovers were targeted phishing against hotels or accommodation providers, not compromise of Booking.com’s backend system or infrastructure.

The Storm-1865 campaign

Microsoft Threat Intelligence identified a campaign beginning in December 2024 and continuing as of February 2025. It impersonated Booking.com in emails to hospitality organizations across North America, Oceania, South and Southeast Asia, and Europe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

The messages directed recipients to fake CAPTCHA pages and used the ClickFix technique, which socially engineers a victim into performing a supposedly corrective action that delivers malware. Microsoft identified payloads including XWorm, Lumma stealer, VenomRAT, AsyncRAT, Danabot and NetSupport RAT. These tools can steal credentials or provide remote access, allowing attackers to reuse hospitality staff accounts.

Was Booking.com itself hacked?

The evidence supports a qualified answer:

  • The 2023 incident was a disclosed implementation weakness in a Booking.com Facebook OAuth flow. It was remediated, and no in-the-wild exploitation was known when Salt reported it.
  • The provider takeovers tracked by Action Fraud were assessed as targeted phishing, not a breach of Booking.com’s backend infrastructure.
  • Microsoft’s later campaign used impersonation, malicious pages and malware against hospitality organizations. A convincing Booking.com-branded email can therefore originate from an attacker-controlled system even when Booking.com’s core platform has not been breached.

For a traveler, the practical question is whether the message or reservation change can be verified through an independently opened Booking.com session and a trusted property contact—not whether the branding looks genuine.

Rank #4
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

What to do when a message asks for payment or card details

If you are a traveler

  1. Do not click links, open attachments or reply to an unexpected request for a password, card number, “verification” payment or urgent cancellation.
  2. Open the official Booking.com app or type the website address yourself and check the reservation there.
  3. Call the property using a number obtained independently, rather than one supplied in the suspicious message. The Swiss National Cyber Security Centre gives this verification approach for Booking.com-related phishing.
  4. If you entered credentials or payment information, change the affected password from the official site, enable two-factor authentication, contact your card issuer about suspicious transactions and report the incident through Booking.com’s official support channel.

If you work for a property

  1. Stop using the link or attachment and disconnect a device that may have run a fake CAPTCHA or downloaded a file.
  2. Notify the person responsible for the property’s Booking.com extranet and IT security immediately; preserve the email, sender details and malware alerts for investigation.
  3. Change credentials from a clean device, revoke active sessions where the account allows it, and enable MFA before resuming normal work.
  4. Verify any request to refund, redirect payment or disclose guest information through a separate, known contact method and an internal approval process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Controls that address the documented risks

Enable Booking.com two-factor authentication

Booking.com says that when a username and password are compromised, it sends a unique verification code to the user’s mobile device before access is granted. Turn on 2FA for every eligible traveler and partner account, and protect the associated phone number and email account as well.

Train staff to reject urgency

Booking.com recommends staff education, MFA, anti-malware software and good account hygiene. Training should specifically cover urgent booking, cancellation, payment and verification requests, because those themes appeared in the provider-focused attacks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Use endpoint protection and account hygiene

Keep operating systems, browsers and anti-malware tools current; use separate credentials for the Booking.com extranet; and prevent ordinary staff accounts from installing software. These controls reduce the chance that a fake CAPTCHA or ClickFix instruction turns one click into a stolen session.

Verify before acting

Booking.com’s traveler guidance warns about sign-in requests and requests for personal or financial information. Treat an unexpected message as untrusted until the reservation is confirmed inside the official app or site and the property is reached through an independently sourced number.

Strengthen OAuth token protection

For developers maintaining OAuth integrations, RFC 9700 recommends sender-constraining access tokens, including mutual TLS or DPoP. Binding a token to the legitimate client or sender limits what an attacker can do with a stolen token and complements secure redirect handling, short token lifetimes and careful session invalidation.

If you suspect an account takeover

  • Use a clean, trusted device to change the password and enable 2FA.
  • Review reservations, messages, profile details, payout or payment settings and recent sessions for unauthorized changes.
  • Contact affected guests or the property through verified channels if a fraudulent message may have been sent from the account.
  • Ask your bank or card issuer to block or monitor transactions when payment details were exposed.
  • Report the incident to Booking.com and the relevant national fraud-reporting service, retaining copies of the original messages and timestamps.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.