Criminals are using leaked hospitality data to target South African travellers with reservation-hijack scams.
The fraud involves stolen booking information or compromised hotel accounts being used to impersonate accommodation providers. Victims are then contacted and asked to provide payment or bank card details.
Hotel Booking Scams Exploit Leaked Customer Data
Hospitality Technology International (HTI) managing director Rory Montgomery previously warned that South Africa’s hospitality sector was being targeted by cybercriminals.
In June, HTI’s property management cloud system was breached by a Russian threat actor using an AI-powered attack technique. Researchers said the incident exposed about two million records containing customer information.
[Meta Tests AI Replies On Threads As Platform Adds Grok-Style Context Feature]
The leaked information reportedly included names, email addresses, phone numbers, check-in and check-out dates and hotel names.
Two months earlier, Booking.com warned South African users that unauthorised third parties may have accessed booking information. The potentially exposed details included names, contact information, booking details and information shared with properties.
South Africa Hotel Scams Use Fake Payment Requests
Cybersecurity educator Boikokobetso Makhetloane said criminals can take control of hotel accounts and impersonate accommodation providers.
“Reservation-hijack scams are when a scammer takes over a hotel’s account and begins impersonating the hotel,” he said. Scammers can then use genuine booking information to make their messages appear legitimate.
Makhetloane said the scams commonly involve phishing messages designed to obtain financial information.
In one example, victims were told they needed to pay the outstanding balance for their accommodation through a link. The message warned that the link would expire within five to 10 minutes and that the booking could be cancelled.
Hotel Booking Scam Red Flags To Watch
Makhetloane said the scammers are often trying to obtain card details rather than simply collect an immediate payment.
“It’s not about you making the payment, it is about you inputting your card details to authorise the payment to go through. They are looking for and harvesting your card details,” he said.
SEE TODAY'S TOP HEADLINES ACROSS LEADING PUBLICATIONS
Travellers with recent hotel bookings have been urged to carefully verify unexpected messages requesting payments or personal information.
The safest approach is to contact the accommodation provider using an official telephone number listed on its website. Customers should avoid relying solely on contact details or links contained in suspicious emails or SMS messages.


