A message says your card couldn’t be verified and your hotel booking will be cancelled unless you confirm it now. Sometimes it even quotes your real hotel and dates — because it came through a hacked hotel’s own chat. It’s a phishing scam either way. Here’s how it works, the tells, and the safe way to check.
Published 6 August 2026 · ~7 min read · By the Phixo team
Travel is the perfect cover for a scam. You’ve paid real money, a trip is coming up, and the fear of arriving to find no room is sharp and immediate. So when an email or message arrives claiming your Booking.com reservation can’t be confirmed because your card “failed verification,” the pressure works — especially with a countdown attached.
This scam has a nastier twist than most. In the ordinary version, it’s a lookalike email from a spoofed domain. But in a version that’s been widely reported, scammers first break into a hotel’s Booking.com account and message guests through the platform’s genuine chat and email — so the message carries your real name, real hotel, real dates, and arrives looking entirely official. The details are stolen; the request is still the trap. Here’s how to tell.
Booking.com does not ask you to “re-verify” your card through an emailed link on a deadline, and it does not threaten to cancel a confirmed reservation unless you type your card details right now. Card management lives inside your account and the app. Treat any “verify your card or lose your booking” message as phishing — even one that quotes real trip details. The safe check: ignore the link, open the official Booking.com app (or type booking.com yourself), and look at your trip there. If the app shows it confirmed with no action needed, the message was the fake.
The goal is always your card details, reached one of two ways:
Why the second version is so effective: every “is this real?” instinct you have — correct hotel, correct dates, arrived through the app I trust — says yes. The one thing that stays constant is the ask: enter your card on a linked page to avoid cancellation. That request is never legitimate, no matter how real the wrapper looks.
This is the core of it. A confirmed booking doesn’t need your card “re-verified” by clicking a link. Any request to confirm card details to keep a reservation is the scam itself.
“Within 12 hours or your booking is released.” The countdown exists to make you act before you check. Real reservations don’t evaporate because you didn’t click an email fast enough.
Click the sender name and hover the button to read the true destination. Booking.com’s email and links live on booking.com.
A domain that merely contains the word “booking” is not booking.com. (In the hacked-hotel version the sender may genuinely be the platform — there, tells 1, 2 and the off-site payment link do the work instead.)
Booking.com handles payment within its own system. A message steering you to an external site or a bank transfer to “hold” the room is going somewhere Booking.com doesn’t operate — and can’t protect you.
“Dear Guest” in the spoofed-email version. (The hacked-hotel version may use your real name, so treat this as a supporting tell, not a decider.)
Urgency and a form asking for card details in the same message is the fingerprint of almost every payment-phishing scam — the same structure as the fake Netflix “payment failed” email, just wearing a travel theme.
Take the message out of the equation and go to the source:
If the app shows your booking confirmed and asks for nothing, the message was the fake. Report it to Booking.com through the official app or site so they can act on the hotel account if it’s been compromised, and delete the message.
The fake booking message stacks two pressures most scams only get one of: a real financial stake (you’ve already paid) and a hard time limit (your trip is soon). Add a version that arrives through the genuine platform with your real details, and even a careful traveller’s instincts get turned into a liability — everything looks right. That’s exactly why appearance is the wrong thing to judge on, here and everywhere. As with the broader signs of a phishing email, the reliable move isn’t deciding whether the message looks real — it’s refusing to act inside the message at all, and checking your booking where Booking.com actually keeps it. For the technical trail of a spoofed one, our free email header analyzer shows where a message really came from.
Move quickly — the sooner you act, the less the details are worth:
For the complete cleanup, step by step, see what to do if you clicked a phishing link.
No. It doesn’t ask you to re-verify your card through an emailed link on a countdown, and it never threatens to cancel a confirmed booking unless you enter card details immediately. Card management happens in your account or the app. That pressure is the scam.
In one common version, scammers compromise a hotel’s Booking.com account and message guests through the platform’s genuine chat — so it carries real reservation details. The stolen details make it convincing, but the “verify your card” request is still fake. Check your booking only in the official app.
Don’t click the message’s link. Open the official Booking.com app or type booking.com yourself, sign in, and read your trip’s real status. If it’s confirmed and needs nothing, the message was the fake.
Contact your bank immediately to block and reissue the card, change your Booking.com password (and anywhere you reused it), turn on two-factor authentication, and report the message to Booking.com and your national fraud service.
Phixo is a browser extension that checks the email open in your Gmail or Outlook against several of the signals above — sender and domain reputation, link mismatches, lookalike domains, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language, and flags anything suspicious in seconds. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.