Travelers holding Booking.com reservations have been warned about "reservation hijacking" — a fraud pattern in which criminals alter or impersonate a genuine booking to divert payment — with the platform updating warnings and contacting affected customers, per BBC reporting. The advisory lands in a peak spring-booking period and puts the verification burden, in practice, on the guest.
This site publishes information, not booking advice; the checks below describe how the platform's own policies work so travelers can use them deliberately.
What reservation hijacking looks like
The pattern, per the BBC's coverage: a fraudster obtains booking details — through phishing, compromised accommodation email, or fake "confirmation" messages — then poses as the property asking for payment or a switch to a different property at the last minute. Booking.com has cautioned that genuine payment requests come through its platform, not by email link or bank transfer requested over the phone.
Related stories: Venice access fee returns April 3: 60 charged days at €10 for day visitors in 2026 · Europe's summer 2026 demand shifted north, and September is the fastest-growing booking month.
The policy levers travelers underuse
Two platform policies are worth knowing before trouble starts. First, per Booking.com's partner help documentation, guests on many non-refundable bookings can make one date change to their stay without forfeiting the booking — a flexibility most travelers assume non-refundable rates exclude. Second, the platform's terms route payment protection and customer service through bookings made and paid on the platform itself; a guest who moves payment off-platform to satisfy a suspicious request generally forfeits those protections.
The three-minute pre-arrival check
Three checks catch most of the documented fraud patterns. Verify all messages inside the Booking.com app or website inbox rather than email links. Confirm any property-change or payment request by calling the property on an independently found number — not one supplied in the suspicious message. And keep payment on-platform; an off-platform bank transfer has no recourse path if the request was fake.
The broader context: online travel platforms concentrate both convenience and fraud risk, and their safety guidance evolves case by case. The platform's help center carries the current versions of these policies; the BBC's reporting is the documented record of the hijacking pattern itself.
