Scmagazine
Phishing Campaign 'I Paid Twice' Targets Booking.com Hotels and Guests
First seen 8 Nov 2025, 12:36 UTC
•
•84% similarity
•37.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A phishing campaign named 'I Paid Twice' has been identified, targeting Booking.com hotel partners and their customers. Cybercriminals compromised hotel accounts to send phishing emails that tricked victims into providing banking information through spoofed Booking.com pages. The campaign has been active since at least April 2025 and utilizes advanced social engineering techniques.
ThreatCluster AI