Breaking
Live threat feed May 19, 2026 | 11:53 UTC
4110 CVEs This Month
6 Actively Exploited
2 Ransomware Activity
18 Breaches YTD
Threat Investigation Portal
Investigate an IOC in the live graph workspace.
Investigate IOC
Data Breaches

Booking.com Confirms Data Breach, Initiates Reservation PIN Resets

Booking.com Confirms Data Breach, Initiates Reservation PIN Resets

Booking.com confirmed a data breach involving unauthorized access to its systems, which exposed sensitive reservation and user data. As a result, the company has initiated a reset of reservation PINs tied to affected bookings to enhance user security.

What happened

Booking.com detected unauthorized access to its internal systems, which led to the exposure of sensitive data related to reservations and users. The company publicly acknowledged the breach following its discovery and took immediate mitigation steps to protect affected accounts. Among these measures was the reset of reservation PINs used to access booking information, aiming to prevent further unauthorized use.

Why it matters

The breach affects users’ private reservation details, potentially putting their personal information at risk. Reservation PINs are typically used as an additional layer of security to verify identity or manage bookings without requiring full login credentials. Unauthorized access or compromise of these PINs can therefore lead to misuse or fraud.

What security teams should do

Security teams should review Booking.com’s official communications for guidance and confirm resets and any recommended password or PIN changes with affected users. Organizations with travel management responsibilities might also consider verifying the integrity of travel booking data and monitoring for suspicious account activities. Users impacted should be informed of the reset and advised on recognizing phishing attempts or other follow-up scams.

Key technical details

While Booking.com has not disclosed detailed technical specifics about the breach or the method of unauthorized access, the company confirmed exposure of sensitive reservation and user data that necessitated resetting reservation PINs. No additional details about the vulnerability exploited or the scope and depth of data accessed have been publicly shared at this time.

Affected organizations/products

The breach affects Booking.com customers whose reservation and user information were accessed without authorization. The exact number of impacted individuals or reservations has not been disclosed.

Source attribution

https://www.bleepingcomputer.com/news/security/new-bookingcom-data-breach-forces-reservation-pin-resets/

Thirumala Rao Padilam
Written by
Thirumala Rao Padilam
error: Content is protected !!