The Booking.com data breach has exposed an undisclosed number of customers’ personal details, including names, contact information, and reservation data, the company confirmed on April 13, 2026. Unauthorised third parties gained access to guest booking information on the platform, which lists more than 30 million accommodation venues worldwide.

The company said it detected suspicious activity involving unauthorised access to guest booking records. Upon discovering the activity, Booking.com said it took steps to contain the issue, updated PIN numbers for affected reservations, and notified impacted customers directly.

What Information Was Accessed

According to an email sent to affected customers, the accessed data may include booking details, names, email addresses, physical addresses, and phone numbers linked to a previous reservation. Any information a customer shared directly with an accommodation provider may also have been exposed.

A company spokesperson confirmed that financial information was not accessed in the breach. Booking.com declined to state how many customers were affected by the incident.

Booking.com Data Breach: Company Background

Booking.com is headquartered in Amsterdam and connects millions of travellers with accommodation, transport, and experiences globally. The platform is owned by Booking Holdings, a US company valued at $137 billion that also owns OpenTable, Agoda, and Kayak. Booking Holdings is based in Norwalk, Connecticut, and employs more than 24,000 people worldwide.

A Pattern of Security Incidents

This incident is not the first time Booking.com has faced cybersecurity challenges. In 2018, criminals used phishing tactics to steal login credentials from hotel employees in the United Arab Emirates, gaining access to the booking data of more than 4,000 platform users. Following that breach, Booking.com reported the incident to the Dutch privacy regulator 22 days late, resulting in a fine of €475,000.

More recently, the platform has faced a growing number of online scams, with fraudsters contacting customers to request payment details under the pretense of pre-authorising or verifying bookings, then charging large sums. The broader tourism and travel booking industry is also under pressure to address the spread of fake listings on booking websites.

Outlook and Customer Guidance

Booking.com has not disclosed whether it has reported the latest breach to the Dutch Data Protection Authority, which oversees the company’s compliance with European privacy regulations. Customers who received notification emails are advised to monitor their accounts for unusual activity and treat any unsolicited payment requests with caution.

The incident adds to a broader wave of data protection concerns affecting major online platforms. As digital commerce continues to grow, regulators and consumers alike are calling for stronger safeguards around personal data held by large travel and hospitality platforms.