Booking.com Payment Fraud: How to Protect Yourself

Illustration of a hacker stealing personal and payment data, representing Booking.com extranet payout fraud - Zeevou

Picture your monthly payout landing on schedule, exactly like every month before it, except this time it lands in a stranger’s bank account.

That’s roughly what happened to Polaris Holdings, a Tokyo Stock Exchange-listed operator running 116 hotels. In May 2026, the company disclosed that an unauthorised third party had broken into its group Booking.com extranet account and quietly changed the bank details used to receive payouts for several properties. By the time anyone noticed, around ¥9 million, roughly $60,000, had been diverted from a single property alone. Guests of the same hotels were simultaneously receiving phishing messages built from the same stolen reservation data, a two-for-one payday for the attackers.

It’s not an isolated case, either. In a separate incident reported by Hostaway, an Airbnb host’s payout account was quietly hijacked and redirected for five months before anyone caught it: a total loss of $34,250 in payments the host never saw.

If you manage bookings through Booking.com, Airbnb, or any other OTA, this is worth ten minutes of your attention.

Person holding a bank card while entering payment details on a laptop, illustrating online payment verification - Zeevou
Designed by Magnific

Don’t find out about a payout change from your bank balance. Zeevou’s Check-in Ready status flags a payment mismatch at the reservation level. Get Started for Free

This isn’t guest-facing phishing. It’s a different, quieter scam

Most Booking.com scam coverage focuses on guests: fake “verify your card” messages, WhatsApp links, cancellation threats. That’s real and worth guarding against, but it’s not the scam that costs hosts their income.

The one that does: someone gets into your extranet account, usually via a phishing email aimed at a staff member, sometimes via malware disguised as a routine “guest complaint”, and quietly edits the payout bank details on file. No card is stolen. No guest complains. The booking calendar looks completely normal. The only thing that’s changed is where your money goes next.

Security researchers have tracked an entire underground market built around this: stolen Booking.com extranet logins are bought and sold on cybercrime forums for anywhere from $5 to $5,000 depending on how many properties and active reservations the account controls. Once inside, redirecting a payout takes minutes.

It already has a name, and UK banks are on the hook for it

A fishing hook caught on a bank card resting on a keyboard, symbolising phishing-driven payment fraud - Zeevou
Designed by Magnific

In the UK, this exact pattern falls under what regulators call Authorised Push Payment (APP) fraud, sometimes referred to as mandate fraud: a scammer impersonates someone you trust to get you (or, in this case, your platform) to send money to the wrong account. It’s the same mechanism behind classic invoice fraud and CEO fraud, just wearing a hospitality-industry disguise. Since October 2024, UK banks have actually been required to reimburse verified APP fraud victims, which tells you how seriously it’s now being treated at a policy level.

The scale isn’t small, either. UK’s Action Fraud logged 532 reports of Booking.com -related scams between June 2023 and September 2024 alone, totalling roughly £370,000 in losses.

Why hosts don’t catch it in time

Three things make payout fraud harder to spot than card fraud:

  • Payouts are periodic, not per-booking. Most hosts check a lump sum landing roughly on schedule, not the routing details behind it.
  • The extranet is the single source of truth, until it isn’t. If that account is compromised, the “official” record itself is compromised.
  • Nothing else in your operations flags it. Bookings, calendars, and guest messages carry on exactly as normal, because the fraud lives entirely in one settings field.

By the time a host notices the money’s wrong, it’s often been wrong for weeks or months.

What actually protects you

A few habits close most of the gap:

  1. Enable 2FA on your extranet account and use a unique password, never one shared with any other login.
  2. Reconcile payouts against a source outside the OTA itself. If the only place you can see your payout details is inside the platform someone just breached, you have no way to catch the change.
  3. Treat “urgent” emails about your account or payment settings with suspicion, especially ones that arrive outside your normal support channel.
  4. Check your payout schedule and amount against what you actually expect , not just “did I get paid,” but “did I get paid the right amount, on time, to the right place.”

That third point is where most hosts are exposed, because most PMS setups simply mirror whatever the OTA extranet says. If the extranet’s compromised, your dashboard is compromised too , you’re just looking at the fraud from a different screen.

Where Zeevou fits in

This is exactly the gap Zeevou’s Check-in Ready status and channel API payment data are built to close.

Instead of trusting the extranet as the only record, Zeevou pulls reservation and payment data directly through each channel’s API, independently of manual extranet edits. That gives you a second, independently-sourced view of what should be happening with a booking’s payment and payout status. A reservation only reaches Check-in Ready once its payment details check out against that channel data , so if something’s been altered outside the normal flow, it surfaces as a mismatch before you’re relying on it operationally, rather than showing up as a mystery shortfall in next month’s payout.

In practice, that means an anomaly gets caught at the reservation level, days or weeks before it would ever show up as “why is my payout £2,000 short this month.”

Stop trusting a single login with your payouts.
Zeevou cross-checks every reservation’s payment status against each channel’s own API, so a quietly edited payout account gets caught before it costs you, not after. See How Zeevou Verifies Payouts

Quick answers

What is APP fraud? Authorised Push Payment fraud is when someone is tricked into authorising a payment to a fraudster’s account, usually by impersonating a trusted party: a bank, a supplier, or in this case, a booking platform’s own systems.

Am I covered if this happens to me? UK banks are required to reimburse verified APP fraud victims under rules introduced in October 2024, but reimbursement isn’t automatic or guaranteed, so you’ll need to report it quickly and document everything. Prevention is still far cheaper than recovery.

Is this a Booking.com security failure? The reported incidents trace back to compromised individual hotel and host extranet accounts , usually via phishing aimed at staff, rather than a breach of Booking.com’s own backend. The lesson isn’t “avoid Booking.com,” it’s “don’t let one login be your only line of defence.”

Image by pch.vector on Magnific.

Further Reading

Scroll to Top
Solution lamp for mobile header

Custom Solutions with Zeevou

Discover tailored solutions perfectly suited to your role, business size, and specific use cases.