Booked and Baited: The Rise of Reservation Hijacking

Booking a hotel online has become a ritual of modern travel. A confirmation email arrives, a reservation is filed away, and a few routine updates are expected as the departure date approaches. Increasingly, however, cybercriminals are exploiting that familiar process to target travelers with remarkably convincing scams.
Known as “reservation hijacking,” these attacks use legitimate booking information to impersonate hotels or travel providers. The messages often include accurate details, such as hotel names, travel dates, and reservation numbers, making them appear authentic. They frequently arrive shortly before departure, when travelers are expecting check-in instructions or account updates, and are designed to steal payment information or other sensitive data.
The Perfect Setup
Reservation hijacking begins not with a fake booking but with a real one. Between reservation and arrival, attackers gain access to guest records through compromised hotel systems, phishing attacks targeting employees, or weaknesses in the booking platforms and third-party services that support modern travel. The data can be remarkably detailed, including guest names, travel dates, reservation numbers, contact information, and sometimes payment details.
With the information in hand, criminals do not need to invent a story. They simply insert themselves into one that already exists. Messages arrive by email, text, WhatsApp, or even through a trusted booking portal, appearing to be a routine part of the travel experience. Unlike traditional phishing campaigns, which rely on generic messages and sheer volume, reservation hijacking is a more tailored form of deception, built on familiar, legitimate information.
The request is often simple: verify a payment method, confirm account details, or complete a pre-arrival step. A link then directs the traveler to a convincing imitation of a hotel or booking website designed to capture financial and personal information. What makes the scam effective is its familiarity. The message contains the right hotel, the right dates, and the right reservation number. In an age of personalized digital services, attackers have learned to use those details as proof of legitimacy.
When a Booking Turns Suspicious
While reservation hijacking scams can be difficult to spot, several warning signs may indicate a scam.
- Urgent requests to verify payment information
- Messages that pressure travelers to act immediately
- Links that take travelers outside the original booking platform
- Requests for wire transfers, gift cards, or other unusual payment methods
Cybersecurity experts generally recommend remaining with the platform used to make the reservation whenever possible. If a message raises concerns, travelers should contact the hotel directly using a trusted phone number or visit the property’s official website instead of clicking embedded links. Additional safeguards, including two-factor authentication, retaining booking records, and using traceable payment methods, can further reduce the risk of fraud.
A New Travel Essential: Caution
The rise of reservation hijacking reflects a broader shift in cybercrime, one in which access to legitimate customer data allows scammers to build highly personalized attacks.
For travelers, familiar details can no longer be treated as proof of authenticity. A reservation number, hotel logo, or itinerary that appears exactly as expected may now be part of the deception. Anyone who suspects fraud or has shared payment information should contact their bank or credit card provider immediately. In an era when scams can closely mirror legitimate communications, caution has become as essential to travel as a passport or boarding pass.