Booking.com In-App Messaging Hack Demands Refund of Duplicate Phishing Charge

On September 1st, I made a reservation via Booking.com for a stay from September 13 to September 16 at The Alfred Hotel in Amsterdam, Netherlands, and completed the payment of 417.1 Euros through the platform.

Despite this, a link containing the message "verify your payment/debit card" was sent to us through Booking.com's official hotel messaging panel, appearing alongside my reservation details. Because it appeared within the official communication channel, we believed this request was authentic and were forced to comply with the instructions. During this process, a second charge was drawn for the exact same hotel on September 7, 2026, from my daughter's supplementary credit card (I am the primary cardholder), which amounted to 24,565.44 TL (approximately 417 Euros) due to currency exchange differences. On the bank statement, this transaction appears under the descriptor "magenta pav morausu grc".

Regarding this fraudulent payment request, I have documented the Booking.com messaging screen captures, support chat screens requesting SMS confirmation codes, The Alfred Hotel reservation confirmation document, the relevant WhatsApp Business profile, and the suspicious messages sent to me, as well as bank transaction statements. This evidence clearly demonstrates that the fraudulent redirect was conducted using my Booking.com reservation and contact details to project an impression of an official channel.

I demand a clear, written explanation detailing how my family's and my private details, card information, and reservation data fell into the hands of third parties, and which system vulnerability or negligence within your framework allowed this to occur. I demand that the source of this data breach, as well as the responsible individual, department, or business partner, be identified and disclosed to me, and that all necessary internal investigations be conducted immediately.

I believe this incident represents a severe cybersecurity and personal data protection failure stemming from unauthorized access to the hotel panel or relevant channels within the Booking.com system, resulting in the leak of our reservation data. Given that we were forced to rely on a link routed through what appeared to be an official channel, I maintain that full responsibility for the financial and emotional distress suffered lies with Booking.com.

I demand that our hardship caused by this security flaw and data breach within your system be rectified, that the duplicate transaction amount of 24,565.44 TL charged for the same hotel be refunded to us promptly and without deduction, and that I be provided with a written statement regarding how our personal data is protected and what measures will be taken to prevent similar incidents moving forward. I would also like to emphasize that we immediately canceled the supplementary card in question for security purposes to prevent further damages. Otherwise, I will proceed to escalate this matter to the Personal Data Protection Authority (KVKK) and relevant judicial bodies.

Comments