These media reports are REALLY misleading, and I would be fuming if I worked at Booking.com at how much damage these media reports have done to the brand. > The company, which is one of the biggest hotel and holiday websites in the world, has not itself been hacked. > > Instead, criminals have tricked their way into the administration portals of individual hotels that use the service. > > This enables them to send me…
As others have said, requiring two-factor authentication would go a long way to stopping this. Nothing in the report or what you have quoted is misleading.
Booking.com users angry at firm's response to hacks
21–30 of 40 posts
Re: Booking.com users angry at firm's response to hacks
#22These media reports are REALLY misleading, and I would be fuming if I worked at Booking.com at how much damage these media reports have done to the brand. > The company, which is one of the biggest hotel and holiday websites in the world, has not itself been hacked. > > Instead, criminals have tricked their way into the administration portals of individual hotels that use the service. > > This enables them to send me…
Not pretending it's not their problem, as a start
Because it absolutely is
Then, work with hotels so that communications from them are authenticated in some way
Re: Booking.com users angry at firm's response to hacks
#23These media reports are REALLY misleading, and I would be fuming if I worked at Booking.com at how much damage these media reports have done to the brand. > The company, which is one of the biggest hotel and holiday websites in the world, has not itself been hacked. > > Instead, criminals have tricked their way into the administration portals of individual hotels that use the service. > > This enables them to send me…
Are you sure? This makes it sound like whatever account hackers gained control of was able to send messages directly to the app. If they log into a booking.com portal to do that, and booking.com hasn't set up multifactor authentication, they aren't blameless.
Re: Booking.com users angry at firm's response to hacks
#24These media reports are REALLY misleading, and I would be fuming if I worked at Booking.com at how much damage these media reports have done to the brand. > The company, which is one of the biggest hotel and holiday websites in the world, has not itself been hacked. > > Instead, criminals have tricked their way into the administration portals of individual hotels that use the service. > > This enables them to send me…
> Genuinely: What do people here think that are Booking.com supposed to be doing about this? Not having a messaging system that lends authority to messages if they aren't able to secure it (including assuring that partners with access secure their ends) adequately for the appearance of authority that is created.
Re: Booking.com users angry at firm's response to hacks
#25Unless they stop using the service then the company won't care that they're angry. What alternatives are people using?
Calling hotels on the phone. When I suggest it to my 30-something peers they look at me like I have two heads though.
Re: Booking.com users angry at firm's response to hacks
#26Earlier quoted context omitted.
As others have said, requiring two-factor authentication would go a long way to stopping this. Nothing in the report or what you have quoted is misleading.
Most popular forms of two-factor are still phishable. WebAuthn/passkeys are a better solution.
Re: Booking.com users angry at firm's response to hacks
#27Earlier quoted context omitted.
> Genuinely: What do people here think that are Booking.com supposed to be doing about this? Not having a messaging system that lends authority to messages if they aren't able to secure it (including assuring that partners with access secure their ends) adequately for the appearance of authority that is created.
The messaging system is full of disclaimers ("The content of the message from Malmaison was not generated by Booking.com") and, looking at a message I've received, it doesn't even support links. Anyone getting phished would have to manually type in a URL in their address bar if this was the vector used.
They post bank account details for the customer to send a payment to.
Manually typing a link may not seem suspicious to many customers anyway.
Edit: Looks like the scam may involve credit/debit cards and links. The messages may be sent to customers via email, and the links are clickable that way. Not sure if that's an email client thing or if Booking.com makes them clickable in HTML.
Re: Booking.com users angry at firm's response to hacks
#28My mother (against my strong advice) booked something on booking.com for ~$6.5K and then couldn't find any evidence of in their "My Trips" interface. I advised her to call the credit card and file fraud. Instead, the customer support agent of the credit card gave her some 1-800 number for booking.com customer support (Booking.com doesn't offer 1-800 number) and when she called it, someone with strong Indian accent wo…
Re: Booking.com users angry at firm's response to hacks
#29Earlier quoted context omitted.
The messaging system is full of disclaimers ("The content of the message from Malmaison was not generated by Booking.com") and, looking at a message I've received, it doesn't even support links. Anyone getting phished would have to manually type in a URL in their address bar if this was the vector used.
I don't think the scams use links. They post bank account details for the customer to send a payment to. Manually typing a link may not seem suspicious to many customers anyway. Edit: Looks like the scam may involve credit/debit cards and links. The messages may be sent to customers via email, and the links are clickable that way. Not sure if that's an email client thing or if Booking.com makes them clickable in HTML…
This is even less credible to me than a phishing site set-up to take card details. As soon as you try to make a payment to a scammer's bank account, confirmation of payee will fail because the bank details won't match the hotel's. It should also raise alarm bells because it's a completely out-of-character thing to be asked to do prior to a stay with a hotel.
Re: Booking.com users angry at firm's response to hacks
#30These media reports are REALLY misleading, and I would be fuming if I worked at Booking.com at how much damage these media reports have done to the brand. > The company, which is one of the biggest hotel and holiday websites in the world, has not itself been hacked. > > Instead, criminals have tricked their way into the administration portals of individual hotels that use the service. > > This enables them to send me…
As others have said, requiring two-factor authentication would go a long way to stopping this. Nothing in the report or what you have quoted is misleading.
Any reasonable person would read this headline and assume Booking.com's platform had been hacked.
> Criminals then send a Google Drive link to the staff saying that it contains an image of the passport. Instead the link downloads malware on to staff computers and automatically searches the hotel computers for Booking.com access.
How would 2FA stop this?