- Never act on the message itself. Close it, open your booking independently in the app or by typing the website address yourself, and act only on what you find there.
- A message can arrive inside your genuine booking thread, from the hotel's genuine account, quoting your real reference. That does not make it real.
- “Contact the hotel directly” is the standard advice and it is the wrong advice here, because the hotel's own channel is the one that has been compromised.
- Hotels genuinely do ask for card details, at check-in, for deposits and for tourist tax. What they do not do is ask you to pay through a link in a message.
- If you already paid, your route back depends on how you paid. Credit card, debit card and bank transfer are three different systems with three different rules.
If a message about your booking asks you to pay, reconfirm your card, or click a link to stop your room being cancelled, do not act on the message. Close it. Open the booking yourself, either in the app or by typing the website address into your browser, and check whether the request appears there. If it does not appear in your booking and it is not in the property's published payment policy, it is not real. That single habit defeats every version of this scam.
Do hotels ever really ask for card details before you arrive?
Yes, and this is why the usual advice fails people. Anyone who travels regularly knows hotels ask for a card. They ask at check-in. They take pre-authorisation holds. They collect city and tourist taxes, and they take damage deposits on self-catering places. So “never give a hotel your card details” is advice that readers already know from experience is wrong, which is exactly why they hesitate when a request arrives.
The useful line is not whether a hotel asks. It is how and where.
Booking.com could not be clearer on this, and it is worth reading twice: no legitimate transaction will ever require you to pay with gift cards or to share your credit card details by phone, text message or email. In statements to UK press it has added WhatsApp to that list explicitly.
So the genuine version always happens in one of two places. Either in person at the property, or inside the booking platform's own secure payment flow, which you reach by opening the platform yourself. It never happens through a link someone sent you.
One complication worth knowing, because it trips people up. Some genuine hotels do use third-party payment processors, so a legitimate payment page can carry a company name you have never heard of. This is why “anything off-platform is a scam” is too blunt a rule to rely on. The test that works is whether the request matches the property's published payment policy and appears in your booking when you open it yourself.
Spain deserves a mention of its own here, because its front desks ask for more than most: hotels there are legally required to register who is staying, so the desk will want your passport as well as a card. That request is real, and our guide to what hotels in Spain can and cannot do with your passport separates the legal part from everything else. The UK has a register of its own, though a much lighter one, and what a UK hotel is actually entitled to ask for sets out where the law stops and house policy starts.
Before you book anything, read the property's payment and damage deposit policy, and the additional fees section. That is your baseline. If a request later arrives that is not described there, you already know it is wrong, and you know it in seconds rather than after twenty minutes of worrying.
How to check a message that's inside your real Booking.com chat
This is the part almost every guide gets wrong, so let's be precise about it.
There are two different attacks. In the simpler one, a message arrives by WhatsApp, text or email, quoting accurate booking details and pointing at a fake payment page. That one is unpleasant but recognisable.
The harder one works like this. Criminals phish or infect a hotel's own booking-system credentials, take over the property's account, and then message guests through the platform's official messaging system. The message lands in your genuine booking thread. It comes from the genuine hotel account. It quotes your genuine reservation. It usually creates urgency about a cancellation and asks you to verify a card.
In that scenario, “contact the hotel directly to check” is useless, because the hotel's channel is the compromised one. Ringing a number printed in the message is worse than useless.
Switzerland's National Cyber Security Centre sets out the routine that still works, and it is the clearest statement of it anywhere: if you are unsure whether a message is legitimate, log in to your booking account directly through the official app or website, without using any links from the message, or call the hotel on a number that you have looked up yourself.
Hong Kong's computer emergency response team makes the same point from the other direction, and it is the sentence to remember: do not assume a message is genuine simply because it contains your name, the hotel name, your booking details or your itinerary.
So the routine is four steps, and none of them involve replying.
- Do not click anything in the message and do not reply to it.
- Leave the thread entirely. Open the app from your home screen, or type the website address into the browser yourself.
- Find the booking and see whether the payment request exists there. Compare it against the payment policy you read when you booked.
- If you still want to speak to someone, look the number up independently. Use the platform's customer service listed on its own site, not the contact details in the message.
You will never be asked to scan a QR code or hand over login details to receive a refund. A refund does not need your card number, your password or your banking app. If a message frames any of those as necessary to give you money back, that is the tell.
Why the message knows your booking reference
Because for a lot of people, it genuinely does have their details, and pretending otherwise helps nobody.
In April 2026, Booking.com began telling users their details had been exposed in a data breach. According to reporting by The Register, the exposed information appears to have included names, contact details, reservation dates, and the messages exchanged with hotels through the platform. Financial data was not accessed. Booking.com also reset booking PINs as a precaution.
The detail that matters for this article is the one about messages. It is not just that a criminal might know your hotel and your dates. It is that the earlier conversation you had with the property, the special request you made, the arrival time you gave, may be visible too. That is why a fraudulent message can echo a real conversation back at you convincingly.
Two things we are not going to claim, because they are not established. The route into that data has not been disclosed, and Booking.com did not respond to The Register's request for comment on it, so anyone telling you confidently how it happened is guessing. And the account-takeover technique described above is a separate, long-running problem in the hotel industry rather than a consequence of that incident.
Action Fraud's own alert on this, covering reports between June 2023 and September 2024, is explicit on that second point: the criminals gained access through a targeted phishing attack against hotels, and not through Booking.com's backend systems or infrastructure. Over that period it received 532 reports, with total losses in the hundreds of thousands of pounds.
If you have a trip coming up, you can check dates and availability here:
You already gave your card details. What now?
Phone your bank first, on the number printed on your card or your statement, and do it before you read the rest of this. Freezing the card is the time-critical bit. Everything else can happen afterwards.
Then work out which system you are in, because this is where people lose money unnecessarily. There is a distinction almost nobody explains, and it decides everything.
If money left your account without your authority, the rules are strong. Your bank must refund you unless you authorised the payment, acted fraudulently, or failed to protect your card, PIN or password. Report it within 13 months, and the refund should be with you by the end of the next business day. Note too that the use of your card, PIN or password is not on its own proof that you authorised anything.
If you were tricked into paying, which is what typing your details into a convincing fake page amounts to, that is an authorised payment. The automatic next-day refund does not apply. You are into chargeback, Section 75 or the push-payment reimbursement rules instead, and those have caps, deadlines and conditions.
Not every unexpected hotel charge is a scam. If the payment is genuinely from the hotel and the reason given is damage, that is a different argument with a different burden of proof, and our guide to what a hotel must evidence before charging you for damage walks through it.
| How you paid | Your route | Scope | Deadline |
|---|---|---|---|
| Credit card, over £100 | Section 75 | A legal right. Card issuer is jointly liable, up to £30,000 | Years, commonly cited as up to six |
| Debit card, or credit card under £100 | Chargeback | A card scheme rule, not a legal right. Any amount | Broadly 120 days, longer for future travel |
| Bank transfer you were tricked into | Statutory reimbursement rules | UK Faster Payments and CHAPS, up to £85,000, minus an excess of up to £100 | 13 months |
| Taken without your authority | Unauthorised payment rules | Bank must refund unless you authorised it or were grossly negligent | 13 months, refund by next business day |
One honest warning about Section 75, because it is oversold everywhere. It requires a direct link between you, your card issuer and the supplier. If your money went to some unrelated payee through a fraudster's page, that link may be broken and the claim can be refused on exactly that basis. Put the claim in anyway, and if it is refused take it to the Financial Ombudsman Service. Just do not treat it as a guarantee.
The bank-transfer rules are the newest piece. Since October 2024, UK banks have had to reimburse eligible victims of authorised push payment fraud sent by Faster Payments or CHAPS. Reimbursement is usually within five business days. It can be withheld for first-party fraud or gross negligence, which is a high bar and one the bank has to prove. Card payments are outside that regime entirely, which is the single most common misunderstanding on this topic.
Where to report it in the UK
Reporting matters even when you get your money back, because these alerts are built from reports.
- Your bank first, using the number on your card or statement.
- Action Fraud at reportfraud.police.uk or on 0300 123 2040, covering England, Wales and Northern Ireland.
- Police Scotland on 101 if you are in Scotland.
- The platform, through its customer service, reached from its own website or app rather than from the message.
- Phishing emails to report@phishing.gov.uk, and scam texts forwarded to 7726.
- The Financial Ombudsman Service if your bank handles the claim badly.
Holiday fraud has a season, and it helps to know where you are in it. Action Fraud recorded 6,066 reports of holiday fraud in 2024, with July the single heaviest month at 647 reports, and total losses well into the millions of pounds. Barclays puts the peaks in April and again in August. In other words, these messages spike exactly when the most people have live bookings sitting in an app.
How to stop this happening next time
Read the payment policy before you book, not after something goes wrong. It takes half a minute and it gives you the baseline that makes every later request easy to judge.
Pay by credit card where you reasonably can, because Section 75 exists for credit and not for debit. Turn on your bank's transaction alerts so an unexpected payment reaches you in seconds rather than at the end of the month. And treat urgency itself as the warning sign. Real hotels do not threaten to cancel your room in the next two hours over a card verification, and the pressure to act immediately is doing more work in these messages than any technical trick.
None of this is a reason to stop booking online. The mechanism criminals are exploiting is a hotel's compromised account, not the act of booking, and the check that defeats it takes about fifteen seconds. Open the app yourself. If the request is not in your booking, it is not real.
Search places to stay for your dates
Both of these are worth a look while you are here: our guide to the pre-authorisation hold hotels put on your card at check-in covers the one card request that is genuine and still catches people out, and our guide to what you are owed when a hotel has no room for you covers your rights for the day a hotel cannot honour the booking at all.
