Skip to content
How to protect yourself from data breaches when booking travel

How to protect yourself from data breaches when booking travel

Canberratimes.Au • September 13, 2026

Every time you book a hotel room or reserve a flight online, you leave a trail of digital breadcrumbs behind.

On their own, your name, date of birth or flight numbers might seem harmless. But if cybercriminals access numerous customer databases through data breaches, they can begin to assemble a master blueprint of your life.

As major travel brands fall victim to third-party data breaches with alarming frequency, a scary question arises: once your travel footprint is out on the dark web, what can scammers actually do with it - and can you stop handing over the keys?

Connecting the dark web dots

Quest Apartment Hotels sent an email to customers last month warning them their names, email addresses, dates of birth and other details had been leaked due to "unauthorised access to a database system arising from a vulnerability through a third-party service provider".

A similar breach affected Booking.com customers earlier this year.

And we all remember the Qantas cyber incident compromising the data of millions of customers, also this year.

Samuel Spencer, a data breach and data governance expert and adjunct professor at the University of Canberra, said once your data is out there, it's "very difficult to unleak that information".

"And now you've got attackers who have Booking.com information, they've got Quest information, they've got Qantas information ... you buy those three data sets on the dark web, you join them together, and you've got a very rich profile of who an individual is, where they stay, how they travel, how they fly," Spencer told Explore .

Data can be used to individuals with fake texts or emails aiming to steal money, called phishing. The information can also be used to make scam calls seem more legitimate.

The more data an attacker has access to, the more targetted and convincing they can make their scams.

Data can also be used for artificial intelligence machine learning, for targetted marketing and sales, and identity theft, which is the ability to use your data to impersonate you.

The power of saying 'no'

Spencer said the single biggest rule of thumb is that the customer can control the amount of data they hand over.

"That's probably the best preventative thing they can do to protect themselves in the future," Spencer said.

Customers have the power to leave optional fields blank, decline marketing consent checkboxes or refuse unnecessary profile creation.

However, there is certain information travel organisations need to collect to secure a booking, said David Beirman, adjunct fellow in management and tourism at the University of Technology Sydney.

"The advanced passenger information that airlines and hotels require will vary between international and domestic destinations," Beirman told Explore .

"From a domestic perspective hotels require a photo ID such as a drivers' license which includes the address of the holder. International guests would be required to show passport numbers and proof that there is at least six months remaining validity on the passport."

Tyler McGee, head of Asia Pacific and Japan at McAfee, said a travel provider would need basics like your name, and payment information, and some bookings could require your date of birth or passport details.

"But not every piece of information you're asked for is necessarily essential. If you're not sure why something like your address is needed, ask. A good rule is to only what you actually need to complete the booking," McGee told Explore .

He said "if a field is optional, think twice whether you need to it".

"The less personal information you hand over, the less there is to potentially expose," McGee said.

He suggested using unique passwords for online accounts and turning on multi-factor authentication where you can.

If there is a breach and you're affected, "be extra cautious".

"Scammers can use exposed information to make messages a booking, refund or account look much more convincing. If you get one, go directly to the company's website or app rather than clicking the link," McGee said.

Sarah is Explore's Digital News Editor. She believes regional travel is just as fun (if not better) than staying in the big cities and loves any travel experience to do with nature, animals and food!. My all-time favourite destination is ... Cornwall. From the giant seagulls to the blustery beaches, Cornish pasties and fishing villages, it stirs something romantic and seafaring in me. on my bucket list is … Mongolia. I want to go somewhere really unique that feels totally foreign and challenges my way of life. My top travel tip is … Don’t plan too much. Walk the streets and let it happen. And make sure you check out what’s within a few blocks of your hotel - sometimes the best local food is found that way.

Are you giving travel sites too much data? How to protect yourself from hackers

The simple habits that stop cybercriminals in their tracks.

How I discovered a blissfully quiet way to experience Japan's best sights

This isn't your typical packed tourist trip to Tokyo.

This scenic Irish coastal train ride reveals Dublin's best-kept secrets

From clifftop hikes to celebrity haunts, this suburban railway is made for side trips.

This Victorian town was once scandalous and wild. Now it's having a revival

Often bypassed, the layered destination is teeming with the unexpected.

Visit the real-life locations where cult TV show Twin Peaks was filmed

These old timber towns in Washington state attract visitors all year round.

These 25 sneaky travel scams are tricking even the most experienced travellers

It's the beginning of the end for Qantas' superjumbo: so what's coming ?

Major international airline to fly from Western Sydney Airport - cheap fares on offer

The popular domestic flight up to 60% cheaper from Sydney's new airport

How these retirees took a government-backed gap year in paradise - and you can, too

Extracted Entities