Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

The hotel knows your booking and wants another payment. Is the message genuine?

Your name, stay dates and hotel may all be correct while an urgent payment request is still fraudulent. Verify the booking without using the supplied link.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
6 September 2026
READING TIME
8 min read
TOPIC
Human Security
The hotel knows your booking and wants another payment. Is the message genuine?

Your trip is only days away. A message arrives with the hotel’s name, your name and the correct dates. The sender says your payment failed and the reservation will be cancelled unless you enter your card details through a link within the next few hours.

The accurate details are what make the message unsettling and believable. Knowing about a booking does not, however, prove that the payment request came from the hotel or platform. A scammer may have obtained the information from a compromised account, mailbox, supplier system or earlier correspondence.

Do not solve the problem inside the message that announced it

The safest rule is to leave the channel creating the pressure. Do not follow a link from the text, email or booking chat. Open the app yourself or type the platform’s known address, then check the booking status and the payment policy in the original confirmation.

Contact the platform through its official app or website. You can also call the property, but find the number independently on its official site or in your original confirmation, not in the suspicious message. Ask whether payment is genuinely outstanding, what amount is due and which payment method has been approved.

A reply in the same chat saying “yes, it’s us” is not enough. If an account or channel has been compromised, the person answering may be the one who sent the false link.

Real details, unfamiliar payment route

A targeted booking scam can look more polished than generic phishing. It may include a reservation number, dates, amount and property name. Instead of hunting for a spelling mistake, compare the demand with the agreement you already have:

  • did the original confirmation say prepayment, payment at the property or an automatic card charge;
  • do the deadline and amount match the booking terms;
  • does the independently opened app show a payment problem after you sign in;
  • does the message move payment outside the platform to an unfamiliar page, bank transfer or chat app;
  • is a short deadline and cancellation threat taking away your chance to make a call?

A genuine card problem can happen. That does not mean you have to resolve it using the method in an unexpected message.

Simply viewing a page does not automatically mean money has been lost. Close it and do not enter any information. If a file was downloaded, do not open it; contact IT support, particularly if you were using a work device.

If you entered card details or approved a payment, call your bank immediately using the number in its app, on its official website or on your card. Ask it to secure the card and check whether the transaction can be stopped. Report the fraudulent message to the booking platform and property, and preserve screenshots, the page address, time and payment confirmation.

If you entered a password on the false page, change it on the genuine service, close other sessions and enable an additional authentication method. Change it anywhere else you reused it. Report financial loss or attempted fraud to law enforcement and include the evidence you retained.

Business travel adds pressure

At work, a cancellation warning may reach somebody in transit, at an airport or between meetings. That is a poor moment to study booking terms. A travel process should therefore say in advance who verifies an extra charge: the traveller, the colleague who booked the trip or the travel provider.

A useful safeguard is to require confirmation through a known channel whenever the payment method or bank details change. Staff should be allowed to pause for a few minutes without fearing blame for a delay. The scammer is selling urgency; the organisation can give people permission to stop.

What the source confirms and what we infer

In its official safety guidance for travellers, Booking.com advises comparing payment requests with the policy in the booking confirmation, treating urgent demands for payment or off-platform contact cautiously, and using official support channels. That source supports the warning signs and verification steps above.

Leaving the channel that created the pressure and establishing a company approval route for extra travel charges are Breachroad recommendations. They do not mean every additional payment is fraudulent; they ensure that both genuine and false requests face the same safe check.

For a real incident behind this scenario, read about the data breach affecting a booking system used by Polish hotels. You can also see a sample phishing-awareness lesson for hospitality teams. Organisations planning similar exercises can explore Breachroad’s cybersecurity awareness training and phishing simulations.

SHARE / COPY