Booking.com breach exposes customer data and highlights fake‑listing issue
Based on · First reported
Sources

- Cybercriminals have exploited Booking.com, leading to a data breach that exposed customers' names, emails, addresses and phone numbers, while the platform also allowed fake listings and phantom bookings to stay live for up to 24 hours before removal.
- Since 2010 the site has processed about 6.5 billion bookings, but its AI‑powered tools failed to flag a fraudulent holiday‑rental listing for 10 Downing Street, underscoring weaknesses in detection that could affect traveler confidence and booking integrity.
Why it matters
The breach and fake‑listing lapses could erode trust in online travel agencies, prompting airlines and hotels to reassess distribution channels and data‑security safeguards.
How we use AI · Report an error
In this story
Related stories
- Booking Holdings leverages AI to cut service costs and boost bookings
- EU General Court upholds Commission block of Booking's eTraveli acquisition
- Booking.com promotes dark‑sky getaways for Halloween, featuring Lake Tekapo and Atacama
- Air Arabia signs group agreement with Amadeus to enable light ticketing in GDS
- Expedia Taap pilots payment link for agents at ABAV Expo 2026