Hotel name, check-in date, and your name—all correct! A single call could empty your bank account..

Newspoint

Imagine you are planning a Dussehra holiday; you’ve selected your flights and hotel via a booking website, entered all your details, and finalized the reservations. Just then, you receive a call stating there is a payment issue with your hotel booking. The hotel name matches, the check-in date is correct, and your name is right too. Naturally, your suspicions are low; you open the provided link, make the payment, and share details with the person on the call.

Moments later, you realize you have been scammed. You had simply provided travel details—dates, the hotel name, and a phone number—but for cybercriminals, this information is enough to make a fraud attempt appear authentic. Your travel data can now be used to gain your trust through fake messages, impersonation, or even fraudulent websites.

How does the scam begin?

Hero Image

Harisharan Nigam, a retiree from the National Skill Training Institute in Kanpur, now lives in Greater Noida; his wife, Santosh, used to work for the Kanpur Municipal Corporation. Pensioners are required to submit an annual 'life certificate' to the municipal corporation. Deciding to avoid the long commute this time, 72-year-old Harisharan thought he would try to get the task done online. He searched for the Kanpur Municipal Corporation's number on Google and called the first result. The person who answered assured him the job could be done if he simply made a small online payment of two rupees. Harisharan made the payment, but the next day, ₹94,000 vanished from one of his bank accounts. He only discovered the theft when an attempt was made to withdraw money from a second account, prompting an alert from the bank.

On September 23, 2026, *PhocusWire*—a news and analysis website for the travel industry—reported on this very threat. The report states that the stolen travel data isn't limited to just credit card numbers; details such as hotel bookings, hotel names, stay dates, vehicle numbers, or information about trusted business contacts can also be exploited for fraud.

**Real Bookings, Fake Stories**


A recent incident involving Booking.com also highlighted the misuse of booking information. A PhocusWire report notes that the company disclosed in April that unauthorized parties had accessed information such as the booker's name, email, contact number, and booking details. Researchers at Gen Digital documented reservation-hijacking scams involving over 350 hotels and other accommodation properties across more than 50 countries. Cyber ​​fraudsters utilized genuine reservation details to craft messages that appeared to originate directly from the hotel. Where does your travel data go?

Information regarding a single trip is not confined solely to the website where you booked your hotel or tickets. It passes through airlines, hotels, online travel agencies (OTAs), travel management companies, payment providers, airports, and various technology service providers. PhocusWire explains that a single booking may traverse multiple systems, including Global Distribution Systems (GDS), hotel property management systems, OTAs, payment gateways, and other entities. In essence, your data circulates across various platforms alongside your trip; a security breach at one point can have repercussions elsewhere.

**Not Just Bookings—Your Identity Is Also Compromised**


On May 29, 2026, a data breach involving the global corporate travel management company BCD Travel was recorded. Records from Mozilla Monitor—a service that tracks data breaches and leaked private information—indicate that this breach compromised phone numbers, email addresses, physical addresses, names, employer details, job titles, and support tickets. This highlights that a data breach involves more than just the theft of passwords or card details; any detail linked to your identity can serve as the foundation for future fraud.

It all comes down to trust.


Security experts warn that cybercriminals can send messages mimicking legitimate alerts, redirect you to fake login pages, or fabricate claims about failed payments. Stolen credentials can expose user data to other systems, a process now accelerated by AI. AI enables the creation of highly convincing phishing messages in multiple languages.

The danger extends beyond mere data theft; your information can be used to orchestrate elaborate fraud. So, the next time you receive a message regarding a travel booking—even if it appears perfectly legitimate—pause and reflect before accepting it as genuine. The issue is no longer just how a scammer obtained your information, but rather how they might exploit your trust once they have it.

Avoid readily handing over your Aadhaar card at hotels; use an alternative form of identification instead. Furthermore, never click on the top-ranked or "sponsored" links/websites that appear after a search, as these could be scams.

Disclaimer: This content has been sourced and edited from TV9. While we have made modifications for clarity and presentation, the original content belongs to its respective authors and website. We do not claim ownership of the content.