These media reports are
REALLY misleading, and I would be fuming if I worked at Booking.com at how much damage these media reports have done to the brand.
> The company, which is one of the biggest hotel and holiday websites in the world, has not itself been hacked.
>
> Instead, criminals have tricked their way into the administration portals of individual hotels that use the service.
>
> This enables them to send messages and fool customers into paying them instead of the hotel.
Previous headlines from the BBC have been even worse:
- Booking.com users angry at firm's response to hacks
- Booking.com hackers increase attacks on customers
How is this not libel?
Genuinely: What do people here think that are Booking.com supposed to be doing about this? Any sophisticated phishing group aren't going to be making rookie errors like hotlinking images when they set-up a phishing siter impersonating Booking.com. They're already doing DKIM signing, DMARC and SPF.
It's unclear to me if the phishing groups are sending emails out directly using the stolen personal details, or using some sort of in-app messaging functionality. If it's the latter I don't think booking.com even supports linking URLs in messages sent out via this mechanism.