Phishing Campaign 'I Paid Twice' Targets Booking.com Hotels and Guests

Phishing Campaign 'I Paid Twice' Targets Booking.com Hotels and Guests

First seen 8 Nov 2025, 12:36 UTC Infosecurity-MagazineScmagazine 84% similarity 37.9

Article Content

Browse articles
ThreatCluster

A phishing campaign named 'I Paid Twice' has been identified, targeting Booking.com hotel partners and their customers. Cybercriminals compromised hotel accounts to send phishing emails that tricked victims into providing banking information through spoofed Booking.com pages. The campaign has been active since at least April 2025 and utilizes advanced social engineering techniques.

ThreatCluster AI

Community

Browse all →