Apr 13, 2026 • Bill Toulas
New Booking.com data breach forces reservation PIN resets
Booking.com has confirmed unauthorized access to its systems, resulting in the exposure of sensitive reservation and user data. The company is forcing...
Executive Summary
Booking.com has confirmed unauthorized access to its systems, resulting in the exposure of sensitive reservation and user data. The company is forcing reservation PIN resets as a remediation measure. While specific details about the attack vector and threat actor attribution remain limited, this breach poses significant risk to affected users whose personal and reservation information may have been compromised. Organizations leveraging Booking.com for travel arrangements should monitor for phishing attempts and ensure credential monitoring. The breach underscores the importance of securing third-party travel booking platforms and the potential cascading risks associated with centralized travel data repositories.
Summary
Booking.com has confirmed via a statement to BleepingComputer that it has detected unauthorized access to its systems that has exposed sensitive reservation and user data. [...]
Published Analysis
Booking.com has confirmed unauthorized access to its systems, resulting in the exposure of sensitive reservation and user data. The company is forcing reservation PIN resets as a remediation measure. While specific details about the attack vector and threat actor attribution remain limited, this breach poses significant risk to affected users whose personal and reservation information may have been compromised. Organizations leveraging Booking.com for travel arrangements should monitor for phishing attempts and ensure credential monitoring. The breach underscores the importance of securing third-party travel booking platforms and the potential cascading risks associated with centralized travel data repositories. Booking.com has confirmed via a statement to BleepingComputer that it has detected unauthorized access to its systems that has exposed sensitive reservation and user data. [...] Booking.com has confirmed via a statement to BleepingComputer that it has detected unauthorized access to its systems that has exposed sensitive reservation and user data. [...]