Notice regarding data breach involving Booking.com
27th August 2026
The Data Protection Authority has received reports of attempted fraud following a data breach involving the Booking.com website.
The attempted fraud reportedly involves users receiving messages or emails shortly before their scheduled stay, with fraudsters seeking to obtain credit card information through deception.
People who have booked accommodation through the website are advised to exercise caution when receiving messages or emails that appear to be from Booking.com. As a general rule, it is advisable to contact the website independently — rather than replying directly to the message — in order to verify its authenticity.
The Data Protection Authority is currently examining the matter insofar as it concerns the processing of personal data.
