New Booking.com data breach forces reservation PIN resets
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。首先,我得仔细阅读这篇文章,理解主要信息。 文章讲的是Booking.com发生了数据泄露事件。黑客入侵了部分用户的预订信息,包括姓名、邮箱、地址、电话号码以及与住宿提供商的沟通内容。公司已经采取措施,重置了相关预订的PIN码,并通过邮件通知受影响的用户。同时,他们提醒用户注意防范钓鱼邮件和电话。 接下来,我需要提取关键点:数据泄露、受影响信息类型、公司应对措施(PIN重置、邮件通知)、安全提醒。然后把这些信息浓缩成一句话,不超过100字。 可能的结构是:Booking.com遭遇数据泄露,黑客获取了部分用户的详细信息,公司已采取行动并通知用户,提醒警惕诈骗。 最后检查字数,确保符合要求。 </think> Booking.com遭遇数据泄露事件,黑客获取了部分用户的姓名、邮箱、地址等信息。公司已重置相关预订的PIN码并通知受影响用户,提醒警惕可疑邮件和电话。 2026-4-13 17:31:52 Author: www.bleepingcomputer.com(查看原文) 阅读量:10 收藏

New Booking.com data breach forces reservation PIN resets

Booking.com has confirmed in a statement to BleepingComputer that hackers accessed some users' data from booking information associated with their reservations.

The company took immediate action, forced PIN resets for existing and past reservations, and informed impacted users directly via email.

Booking.com is one of the largest online travel platforms in the world, allowing users to book accommodation, flights, car rentals, airport taxis, and travel experiences. The service acts as a middleman between travelers and hospitality providers.

Wiz

As a major player, the service lists millions of properties worldwide and handles hundreds of millions of bookings per year.

Over the weekend, multiple users reported receiving emails from the official [email protected] address, warning of a cybersecurity incident that may have exposed personal information to unauthorized parties. The compromised data types include:

  • Full names
  • Email addresses
  • Postal addresses
  • Phone numbers
  • Communications shared with the property providers

The same notification included an updated PIN for a given reservation number, and urged users to be cautious of suspicious emails and phone calls, reminding them that the service will never ask for sensitive information or bank transfers.

"At Booking.com, we are dedicated to the security and data protection of our guests. In that spirit, we're writing to inform you that unauthorized third parties may have been able to access certain booking information associated with your reservation," reads the company's notification.

Caution is also advised when receiving emails that appear to come from the booked property or Booking.com itself, as the service recommends not clicking any links in such messages.

However, users who received these messages did not receive alerts in the Booking.com app, creating confusion about their legitimacy.

Responding to our requests for comment and information about the incident, Booking.com’s communications lead, Sage Hunter, confirmed the security breach incident via the following statement:

“At Booking.com, we are dedicated to the security and data protection of our guests. We recently noticed some suspicious activity involving unauthorized third parties being able to access some of our guests’ booking information. Upon discovering the activity, we took action to contain the issue. We have updated the PIN number for these reservations and informed our guests” - Sage Hunter, Booking.com

The company did not answer our questions about the number of impacted users, but assured us that everyone will be notified individually. The company also underlines that customer support services in multiple languages are available 24/7.

Some users on Reddit reported over the weekend that they are being targeted by scammers who appear to have private reservation information. However, it is unclear if these reports are related to the latest security breach that Booking.com disclosed.

tines

Automated Pentesting Covers Only 1 of 6 Surfaces.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.


文章来源: https://www.bleepingcomputer.com/news/security/new-bookingcom-data-breach-forces-reservation-pin-resets/
如有侵权请联系:admin#unsafe.sh