Booking.com Reservation BreachesBooking.com Reservation BreachesCoverage from Emery Reddy, Class Action U, and others
00/00/0000
DailyWeekly
This topic centers on Booking.
com and related travel booking portals exposing traveler data through breaches, suspicious access, or insecure third-party systems. The disclosed information commonly includes names, email addresses, phone numbers, addresses, reservation details, and, in some cases, accommodation communications or passport images. The main significance is not direct financial theft but the way booking data can be reused for phishing, reservation hijacking, and other targeted scams.
Looking Back
2797 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Nov '18
Apr '20
Jun '21
Oct '22
Dec '23
Apr '25
Jun '26
History
06/29/2026
The story broadens beyond hotel and booking-system breaches to include a separate travel-document exposure involving passport scans and selfie images stored in public cloud storage. This shifts the emphasis toward travel services broadly serving as a fraud and privacy-risk surface, while Booking.com remains central.
06/07/2026
The story has shifted from a Booking.com-centered pattern of travel-data exposure to a broader hospitality-breach cluster, with a new Dutch hotel incident showing shared software can propagate exposure across many properties. It also now includes stronger enforcement context, including prior regulatory penalties and a fresh GDPR investigation.