Skip to content
Front Desk

Guide

IT security at a hotel: what the Booking.com and Expedia scams reveal

Recent attacks on hotels don't hack the booking platforms: they steal the login details of the staff who use them.

Between 2023 and 2026, a scam campaign nicknamed “I Paid Twice” hit hotels partnered with Booking.com and Expedia in several countries. It doesn't attack the platforms themselves, but the accounts of their hotel clients, before turning on their guests. The mechanism is instructive because it doesn't rely on any complicated technical flaw: it relies on a stolen password.

Gaëtan Grond, fondateur de Front Desk

Dix ans en hôtellerie, en France et au Royaume-Uni, avant de créer Front Desk. Les guides de ce site sont écrits à partir de ce qu'il a vu en réception et avec les équipes clientes.

In brief

The attackers don't hack Booking.com or Expedia: through a fake verification form, they steal the login details of a hotel employee with access to the booking extranet. Once logged in, they read real bookings and contact guests pretending to be the hotel, to get a payment out of them. What protects a team isn't software, it's habits: one account per person, no shared or visibly written-down password, and suspicion of any page that asks for an unusual action to “verify” you're human.

What happened at hotels partnered with Booking.com and Expedia

The scenario, documented by several IT security vendors, starts with an email or message sent to a hotel employee: a booking to confirm, an invoice to check, a verification to complete. The page that opens looks like an ordinary anti-bot check, but it asks for an unusual action, such as opening Windows' “Run” window and pasting in some text. That action actually installs malware that steals credentials saved on the computer, including the booking extranet's.

Once logged in as the hotel, the attackers see real bookings: guest name, dates, reference number. They then contact travellers by message, through the platform's app or via WhatsApp, posing as the hotel, using these exact details to sound credible, and ask them to “revalidate” their card on a fake payment page.

According to Action Fraud, the UK's fraud-reporting body, cited by several specialist outlets, this type of scam generated 532 reports between June 2023 and September 2024 in the UK, for around £370,000 in losses. That figure covers travellers who were deceived, not hotels: their own cost is mostly measured in lost trust and time spent reassuring guests who feel they were scammed by the hotel itself.

Why this scam works

It works because it isn't looking for a flaw in Booking.com or Expedia: those platforms haven't been hacked. It's looking for the easiest link to reach, someone clicking a link during a busy shift, on the computer the whole front desk shares.

It also works because the final message, the one the guest receives, contains real information: their name, their dates, their booking reference. That's what makes it convincing, and it's also what makes the hotel look responsible in the guest's eyes, even though the hotel is a victim too.

The signal to know

No legitimate verification, not from Booking.com, not from Expedia, not from any other service, ever asks you to open Windows' “Run” window (Windows + R) and paste something in to prove you're not a robot. A page that asks for that is trying to compromise the computer, not running an anti-bot check.

What actually protects a team

None of these measures depend on expensive software. They're habits, and they hold up as long as the whole team knows them, not just management.

One account per person, never a shared login

An account used by several people at the counter ends up with a password everyone knows, so it gets written down somewhere to avoid forgetting it. That's often the first link to give way.

Nothing written down in plain sight near a workstation

A password stuck on the screen or slipped under the keyboard cancels out any other precaution. If it has to be written down, it belongs somewhere out of reach of a guest leaning on the counter.

Type the address rather than follow a link

To log into a booking extranet, the safest habit is to type the address directly into the browser rather than clicking a link received by email or message, even when the message seems to come from the platform itself.

Change a password at the first doubt, without waiting for instructions

Someone with a doubt about a message received or a page opened doesn't need to wait for management's approval to change their password. Reporting it afterwards matters as much as having done it right away.

Notify the platform and affected guests when in doubt

If access may have been compromised, both Booking.com and Expedia have a process for securing an extranet account and warning about fake messages. Notifying guests whose bookings may have been seen also limits the damage to trust.

The weak point that never comes from software

At most hotels, the weakness isn't technical, it's organisational: a booking extranet password known to the whole team because it never changes, the same login used across several tools for convenience, a sticky note near the front desk screen. No antivirus fixes that.

The good news is that this weak point gets fixed without buying anything: by giving each person their own access, on every tool that allows it, and by making vigilance about unusual links and pages as much a part of starting a shift as counting the till.

What Front Desk does, and does not, do on this topic

Front Desk has no access to your Booking.com or Expedia accounts, and can neither protect them nor stand in for them: they are two separate systems. What the tool applies is the same principle that protects you everywhere else, to its own tools.

  • Every team member has their own account, with no shared login, on every plan.
  • Data is hosted in France, in Paris, with Scaleway, with automatic backups every 24 hours.
  • Exchanges between your browser and our servers are encrypted.
  • Access to a property's data is restricted to that property's accounts, according to each person's role.

Frequently asked questions

Can Front Desk prevent this kind of scam on Booking.com or Expedia?

No, and it needs to be said clearly: Front Desk has no access to those platforms' extranet accounts and can neither monitor nor protect them. They are entirely separate systems. What Front Desk brings is the habit of one individual account per person, applied to your own internal tools.

Should the team's passwords be changed on a regular schedule?

There's no single rule that suits every property. The principle that protects the most, whatever schedule you choose, is that a password is never shared between several people and never written down in plain sight near a workstation.

How do you recognise a fake verification request?

The most reliable signal is a request for an unusual action: opening Windows' “Run” window, pasting in text provided by the page, or installing anything to “prove you're not a robot”. No legitimate verification asks for that. If in doubt, close the page and log in by typing the usual address directly into the browser.

Where is Front Desk's data hosted?

In France, in Paris, with Scaleway. Exchanges between your browser and our servers are encrypted, and the database is backed up automatically every 24 hours. Full details are in our privacy policy.

See other resources