Picture your monthly payout landing on schedule, exactly like every month before it, except this time it lands in a stranger’s bank account.
That’s roughly what happened to Polaris Holdings, a Tokyo Stock Exchange-listed operator running 116 hotels. In May 2026, the company disclosed that an unauthorised third party had broken into its group Booking.com extranet account and quietly changed the bank details used to receive payouts for several properties. By the time anyone noticed, around ¥9 million, roughly $60,000, had been diverted from a single property alone. Guests of the same hotels were simultaneously receiving phishing messages built from the same stolen reservation data, a two-for-one payday for the attackers.
It’s not an isolated case, either. In a separate incident reported by Hostaway, an Airbnb host’s payout account was quietly hijacked and redirected for five months before anyone caught it: a total loss of $34,250 in payments the host never saw.
If you manage bookings through Booking.com, Airbnb, or any other OTA, this is worth ten minutes of your attention.

Table of Contents
This isn’t guest-facing phishing. It’s a different, quieter scam
Most Booking.com scam coverage focuses on guests: fake “verify your card” messages, WhatsApp links, cancellation threats. That’s real and worth guarding against, but it’s not the scam that costs hosts their income.
The one that does: someone gets into your extranet account, usually via a phishing email aimed at a staff member, sometimes via malware disguised as a routine “guest complaint”, and quietly edits the payout bank details on file. No card is stolen. No guest complains. The booking calendar looks completely normal. The only thing that’s changed is where your money goes next.
Security researchers have tracked an entire underground market built around this: stolen Booking.com extranet logins are bought and sold on cybercrime forums for anywhere from $5 to $5,000 depending on how many properties and active reservations the account controls. Once inside, redirecting a payout takes minutes.
It already has a name, and UK banks are on the hook for it

In the UK, this exact pattern falls under what regulators call Authorised Push Payment (APP) fraud, sometimes referred to as mandate fraud: a scammer impersonates someone you trust to get you (or, in this case, your platform) to send money to the wrong account. It’s the same mechanism behind classic invoice fraud and CEO fraud, just wearing a hospitality-industry disguise. Since October 2024, UK banks have actually been required to reimburse verified APP fraud victims, which tells you how seriously it’s now being treated at a policy level.
The scale isn’t small, either. UK’s Action Fraud logged 532 reports of Booking.com -related scams between June 2023 and September 2024 alone, totalling roughly £370,000 in losses.
Why hosts don’t catch it in time
Three things make payout fraud harder to spot than card fraud:
- Payouts are periodic, not per-booking. Most hosts check a lump sum landing roughly on schedule, not the routing details behind it.
- The extranet is the single source of truth, until it isn’t. If that account is compromised, the “official” record itself is compromised.
- Nothing else in your operations flags it. Bookings, calendars, and guest messages carry on exactly as normal, because the fraud lives entirely in one settings field.
By the time a host notices the money’s wrong, it’s often been wrong for weeks or months.
What actually protects you
A few habits close most of the gap:
- Enable 2FA on your extranet account and use a unique password, never one shared with any other login.
- Reconcile payouts against a source outside the OTA itself. If the only place you can see your payout details is inside the platform someone just breached, you have no way to catch the change.
- Treat “urgent” emails about your account or payment settings with suspicion, especially ones that arrive outside your normal support channel.
- Check your payout schedule and amount against what you actually expect , not just “did I get paid,” but “did I get paid the right amount, on time, to the right place.”
That third point is where most hosts are exposed, because most PMS setups simply mirror whatever the OTA extranet says. If the extranet’s compromised, your dashboard is compromised too , you’re just looking at the fraud from a different screen.
Where Zeevou fits in
This is exactly the gap Zeevou’s Check-in Ready status and channel API payment data are built to close.
Instead of trusting the extranet as the only record, Zeevou pulls reservation and payment data directly through each channel’s API, independently of manual extranet edits. That gives you a second, independently-sourced view of what should be happening with a booking’s payment and payout status. A reservation only reaches Check-in Ready once its payment details check out against that channel data , so if something’s been altered outside the normal flow, it surfaces as a mismatch before you’re relying on it operationally, rather than showing up as a mystery shortfall in next month’s payout.
In practice, that means an anomaly gets caught at the reservation level, days or weeks before it would ever show up as “why is my payout £2,000 short this month.”
Quick answers
What is APP fraud? Authorised Push Payment fraud is when someone is tricked into authorising a payment to a fraudster’s account, usually by impersonating a trusted party: a bank, a supplier, or in this case, a booking platform’s own systems.
Am I covered if this happens to me? UK banks are required to reimburse verified APP fraud victims under rules introduced in October 2024, but reimbursement isn’t automatic or guaranteed, so you’ll need to report it quickly and document everything. Prevention is still far cheaper than recovery.
Is this a Booking.com security failure? The reported incidents trace back to compromised individual hotel and host extranet accounts , usually via phishing aimed at staff, rather than a breach of Booking.com’s own backend. The lesson isn’t “avoid Booking.com,” it’s “don’t let one login be your only line of defence.”
Image by pch.vector on Magnific.

