Global Phishing Campaign Targets Booking.com and Hotels
Article Content
Browse articles
A phishing campaign named 'I Paid Twice' has been targeting Booking.com partner hotels and their customers since April 2025. Cybercriminals are using compromised hotel accounts to send phishing emails that trick travelers into providing banking information through spoofed Booking.com pages. The campaign has been linked to the ClickFix malware, which facilitates the theft of customer data.
Ask AI about this cluster
Answers cite the sources they use
Updated 197d ago How this analysis works
More articles in this cluster (1)
Following this threat?
Track ClickFix and Tourism in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…