The hotel scam so convincing it fools guests with their own booking details
By Harry Dennis • Published: 13 Aug 2026 • 14:34 • 3 minutes read
Criminals pose as hotels on WhatsApp, using accurate reservation details to win the victim's trust. Credit: Wisely / Shutterstock
It gets your name right, your hotel right and even your booking number right, so there is no obvious reason to doubt it. The accuracy is exactly what makes this WhatsApp scam so dangerous, and Spain’s cybersecurity watchdog says it is still catching out holidaymakers this summer.
How a message can be built entirely from real information
Spain’s National Cybersecurity Institute (INCIBE) and the Guardia Civil have renewed their warning over a fraud campaign in which criminals pose as hotels on WhatsApp, using accurate reservation details to win the victim’s trust. The messages typically include the name of the hotel, the guest’s full name, the exact check-in and check-out dates and the genuine booking reference number. INCIBE says this is what separates the scam from ordinary phishing, where a generic greeting or an odd request is usually the first giveaway.
The message claims there is a problem with the payment or the reservation and asks the guest to click a link to confirm their details. That link leads to a fraudulent website cloned to resemble the hotel or the booking platform, where victims are asked to enter card numbers or personal information. The same approach can also arrive by email or on a phone call.
Where the real data is coming from
Booking.com confirmed in April 2026 that unauthorised third parties had accessed customer data, including names, email addresses, postal addresses and phone numbers. INCIBE-CERT has documented more than 4,000 customers whose full details were taken, with around 300 of those cases also involving compromised card information.
Switzerland’s National Cyber Security Centre separately flagged a wave of near-identical messages this year, tracing some cases to hotel staff accounts compromised through phishing or malware rather than Booking.com’s own systems. That gives criminals two distinct pipelines of real data: the April breach for stays already completed, and hijacked hotel accounts for reservations that are still to come.
Guests are already losing hundreds of euros
INCIBE has documented a case in which a customer received messages tied to a genuine booking and later suffered fraudulent card charges. The hotel involved said its own account on the booking platform had been compromised and used to contact guests directly. Spanish consumer group OCU says it has also received complaints from travellers who lost hundreds of euros after trusting messages containing accurate booking information. Reports of fraud linked to travel bookings have risen sharply this summer, when reservation volumes peak and rushed travellers are least likely to double-check a message.
The five signs INCIBE says give it away
A hotel logo and a WhatsApp message alone don’t prove anything, as a quick search on Google can provide a company’s high-def logo, and a professionally redacted message can be written by anyone. INCIBE says even Meta’s “verified business account” badge is no guarantee, and the safest check is comparing the sender’s number against the contact details published on the hotel’s own website.
The web address behind any link is the next tell. If the domain does not match the hotel or the booking platform exactly, it is fraudulent. No genuine hotel asks for card details over WhatsApp to confirm a reservation that has already been made, and messages warning of an imminent cancellation are designed to make guests act before they think.
What to do if you receive one of these messages or have already clicked
Anyone who receives one of these messages should avoid the link, block the sender and check their reservation directly through the hotel’s official website or app, typed in independently rather than reached through the message. Anyone who has already shared card details should contact their bank immediately to block the card and monitor for further charges. INCIBE recommends keeping screenshots of the message, the sender’s number and the fraudulent link, then reporting the incident to the Policía Nacional or Guardia Civil.
Its free helpline, 017, offers confidential advice to anyone who has been targeted, whether or not they have lost money. With August bookings still live across Spain, INCIBE expects the same messages to keep circulating for as long as the summer season does.
Follow Euro Weekly News on Google News
Get breaking news from Spain, travel updates, and expat stories directly on your Google News feed.
Follow on Google NewsSign up for personalised news
Subscribe to our Euro Weekly News alerts to get the latest stories into your inbox!
By signing up, you will create a Euro Weekly News account if you don't already have one. Review our Privacy Policy for more information about our privacy practices.
Harry Dennis
Born in the UK and raised on the Cádiz coast, Harry brings his background in design, music, and photography to his writing for Euro Weekly News, sharing stories that celebrate culture and lifestyle across Spain and beyond.
Comments