Global Phishing Campaign Targets Booking.com and Hotels
First seen 23 Nov 2025, 12:26 UTC
•
•75% similarity
•19.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A phishing campaign named 'I Paid Twice' has been targeting Booking.com partner hotels and their customers since April 2025. Cybercriminals are using compromised hotel accounts to send phishing emails that trick travelers into providing banking information through spoofed Booking.com pages. The campaign has been linked to the ClickFix malware, which facilitates the theft of customer data.
ThreatCluster AI
How this analysis works