All Breaches
April 11, 2026 Verified Sensitive Record Travel

Booking.com 2026 Data Breach

The Booking.com 2026 data breach is a security incident in which the company confirmed that unauthorized third parties were able to access certain reservation information belonging to some guests. Booking.com notified affected people in April 2026 and said the issue had been contained. The company did not disclose how many reservations or people were affected, which system enabled the access, or the exact start date of the technical incident. LeakData therefore records the affected population as unknown and does not present an estimate, an attacker claim, or Booking.com's total customer volume as a breach count.

A Booking.com spokesperson told TechCrunch and SecurityWeek directly that the suspicious activity involved unauthorized parties being able to access some guests' booking information. The company said it acted after detecting the activity, contained the issue, changed the PIN numbers for the relevant reservations, and informed guests. That statement confirms unauthorized access to data, but it does not confirm that Booking.com customer accounts were compromised. This record follows the narrow, verifiable scope described by the company.

Confirmed Types of Data

Customer notices and reports based on the company's statements listed names, email addresses, phone numbers, booking details, and information a guest may have shared with an accommodation through Booking.com. Reservation details can include context such as travel dates, the property name, a booking reference, or accommodation-related information that can make phishing convincing. Booking.com did not say that every possible subfield was exposed for every affected person, so LeakData lists only the main categories expressly reported.

Booking.com said financial or payment information was not accessed. TechCrunch also updated its report, based on a later company clarification, to state that physical addresses were not taken. This record does not list credit card data, banking details, physical addresses, passwords, or account authentication data among the compromised fields. The company's decision to replace reservation PINs was a protective measure and should not, by itself, be treated as proof that attackers obtained those PINs.

Incident Timeline

Booking.com customers began sharing notification messages online during the weekend of April 11–12, 2026. TechCrunch and SecurityWeek published the company's confirmation on April 13, and Help Net Security summarized further details the following day. The company did not disclose the day or time when the suspicious activity first began or was first detected. The April 11 date in LeakData therefore represents the public notification period, not a verified date on which an attacker first entered a system.

The company said it moved quickly after discovering the activity, fully contained the issue, and generated new PINs for affected reservations. Some notified customers reported receiving warnings related to both current and past bookings, but those individual accounts cannot establish the overall scale. Booking.com did not publish a numerical breakdown of affected countries, properties, reservations, or customers, leaving the total population unknown.

Access Route and Account Distinction

Booking.com did not explain whether the unauthorized access came through a vulnerability in its central infrastructure, an accommodation partner account, a support tool, a compromised session, or another route. SecurityWeek specifically noted that it remained unclear whether Booking.com's own systems had been breached. The technical origin is therefore not stated as fact in this record. The event is classified as unauthorized access to reservation data without inventing an undisclosed attack method.

The company also clarified that customer accounts had not been breached. That distinction matters because access to reservation information is not the same as obtaining a user's Booking.com password or authenticated account session. An attacker could see a name, phone number, email address, and travel context without possessing account credentials. LeakData consequently does not add account passwords to the data classes or describe the incident as a broad account-takeover campaign.

Phishing and Reservation Fraud Risk

Reservation information can support targeted fraud even when it contains no payment data. A criminal who knows the real hotel, travel dates, phone number, or booking context can send a convincing WhatsApp message, email, or text requesting an extra payment, card verification, or a new bank transfer. Some customers reported detailed scam messages, but the company did not confirm that every reported message resulted from this incident. The phishing risk is genuine, while the link to each individual fraud attempt remains unproven.

Recipients should review reservations only in the Booking.com app or by typing the official website address themselves, and should avoid payment links embedded in messages. An unexpected request for a bank transfer, card number, verification code, or PIN should be checked through an independent channel. Booking.com reminded customers that it will not request credit card details by email, telephone, WhatsApp, or SMS, or ask for a bank transfer different from the payment instructions in the booking confirmation.

Booking.com's Response

The concrete measures disclosed by Booking.com were containing the suspicious activity, renewing PIN numbers for affected reservations, and notifying the relevant guests. Replacing PINs was intended to reduce the chance that old reservation access information could be misused. While emphasizing that financial data was not accessed, the company urged customers to remain alert for phishing. Public statements did not identify a forensic provider, an attacker, or the architecture of the system through which the data was reached.

The absence of a total affected-person count is the most important limitation of this record. Booking.com's historic booking volume, its global customer base, and speculative figures mentioned in coverage are not verified incident totals. Likewise, online claims attributed to a threat group were not used as a number or as evidence because the company did not validate them. If a regulator filing or a more detailed company update appears later, the count and scope should be revised from that new documentation.

How to Interpret This LeakData Record

This entry documents a real unauthorized-access event supported by Booking.com's direct responses to journalists, while avoiding certainty about technical details the company did not disclose. An unknown affected count does not mean the incident was small; it means no trustworthy total has been published. The listed data classes refer to the limited, undisclosed-size group that received notices, not to every person who has ever used Booking.com.

The verified core fact is that unauthorized third parties could access booking information belonging to some guests. Compromise of payment data and customer accounts was not confirmed, the issue was contained, and the relevant reservation PINs were changed. The most useful defensive step is to distrust unexpected payment messages even when they contain genuine reservation details, and to verify every request through the official application or a separately obtained contact channel.

0
Affected Accounts
5
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

5
Names
Email addresses
Phone numbers
Travel reservation details
User-provided accommodation information

Additional Information

Added DateJuly 26, 2026
Breach DateApril 11, 2026
Domainbooking.com
SourceUnauthorized access
Last Content UpdateJuly 26, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information