She then then got an email supposedly from the Hilton requesting the same
thing. “They had everything like the reservation number, names of guests and
the logos looked accurate.” She ignored the emails after calling
Booking.com, which said it never asked for payment up front. However other
customers paid up.
Booking.com is one of the largest travel websites which claims to book 700,000
rooms a night in more than 200 countries.
The company said it was committed to countering fraud and once it noticed a
guest was affected by phishing activities, it immediately notified the
individual.
Since the fraud, it has made changes so data can only be accessed from a
computer linked to the hotel’s server.
Peter Kornelisse, chief security officer at Booking.com, said: “We estimate
around 10,000 people are affected. We are protecting our customers, hotels
and Booking.com continuously. We have a battle against organised crime.
We’ve made technical improvements in several areas.
“We do inform customers to a certain extent. We can warn today about a
specific scenario that takes place and the next moment we have a different
scenario.
“We contacted all the guests who are affected by the phishing attacks and we
took the burden of our guests.”
The British Hospitality Association said it had been alerted to the con.
Some victims had received phone calls asking them to pre-pay their hotel room
in return for perks including a transfer from the airport, only to later
discover this did not exist and their hotel room had not been paid for, a
spokeswoman said.
Jackie Grech, Legal and Policy Director at the British Hospitality
Association, warned customers to be “extremely cautious” after booking
online.
Jackie said: “We know so far that the scam seems to be limited to a few
customer bookings across a number of four and five star hotels in London.
We have contacted the online booking agent and alerted hotels across the
capital.
“The important message is for customers of online travel agents who need to
be vigilant and if they are contacted by anyone asking them to pre-pay their
hotel room, they should be extremely cautious about doing so. It’s best to
call the hotel directly to check.”
A Hilton Worldwide spokesperson said: “Our initial investigation has found
this incident is not the result of a breach of Hilton systems or websites.
We have asked Booking.com to ensure their investigation is thorough and
appropriate action is taken. Guests who have received suspicious emails
should contact their booking provider immediately and not respond to these
emails.”
