Booking.com Reservation Breaches
Coverage from Emery Reddy, Class Action U, and others

This topic centers on Booking.
com and related travel booking portals exposing traveler data through breaches, suspicious access, or insecure third-party systems. The disclosed information commonly includes names, email addresses, phone numbers, addresses, reservation details, and, in some cases, accommodation communications or passport images. The main significance is not direct financial theft but the way booking data can be reused for phishing, reservation hijacking, and other targeted scams.
The story broadens beyond hotel and booking-system breaches to include a separate travel-document exposure involving passport scans and selfie images stored in public cloud storage. This shifts the emphasis toward travel services broadly serving as a fraud and privacy-risk surface, while Booking.com remains central.
The story has shifted from a Booking.com-centered pattern of travel-data exposure to a broader hospitality-breach cluster, with a new Dutch hotel incident showing shared software can propagate exposure across many properties. It also now includes stronger enforcement context, including prior regulatory penalties and a fresh GDPR investigation.
- Hospecs-linked Dutch hotel breach affected at least 100 hotels.
- A GDPR investigation has been opened into the Dutch hotel incident.
- Earlier Booking.com cases led to penalties for late notification.
- Shared software can spread exposure across many properties.
- Current signal is driven by near-simultaneous 2026 hospitality breaches.
The story has broadened from Booking.com reservation breaches into a wider travel-data exposure pattern that now includes a UK visa portal leaking passport scans and selfies. The framing has also shifted toward vendor and cloud-security failures, with incomplete disclosure emerging as a recurring concern.
- UK visa portal exposed passport scans, selfies, and contact details.
- Insecure cloud storage is cited as a breach vector.
- Companies are withholding affected-user counts and technical scope.
- Historical Marriott/Starwood breach added as context.
- Vendor dependence is now a central risk theme.
Recent coverage is dominated by Booking.com’s April 2026 reservation-data breach and the scam risk that follows from it. The exposed booking details are being tied to targeted phishing, impersonation, and reservation-hijacking attempts, while Booking.com responds with PIN resets and customer notifications.
