Holiday lets owner 'devastated' after Booking.com account attack

Holiday lets owner 'devastated' after Booking.com account attack

Victoria Pollard, who owns the small Exeter-based property management company Life’s 2 Short, described feeling “devastated and exhausted” after discovering thousands of fraudulent property reservations had been made under her company’s name on Booking.com. Some individuals traveling from abroad were left stranded without accommodations due to the bogus bookings. Pollard revealed that her accounts were compromised in August through a phishing attack, which resulted in her losing access and missing legitimate reservations.

Booking.com issued an apology and assured that it was providing “full support” to Pollard. The platform confirmed that all affected listings had been taken down and that customers impacted by the incident were offered alternatives such as relocations, refunds, or free cancellations. A statement from Booking.com explained, “Our investigation indicates the accommodation was likely the victim of a sophisticated phishing attack by cyber criminals, which affected their own computer systems and led to temporary unauthorised access to the accommodation partner’s Booking.com account.”

The small business, which employs only one other staff member, faced harsh backlash from misled guests who believed Pollard was responsible for the fraudulent listings. Pollard shared that she had been subjected to relentless online abuse, with angry customers accusing her of ruining their holidays and lives after having already booked flights. At one point, she was receiving “20 to 30 calls a minute” and was forced to put her phone into airplane mode. She also spent up to 12 hours a day trying to handle and resolve the fallout from the attack.

Consumer expert Kat Cereda from Which? commented on the situation, highlighting that problems like these are unfortunately not uncommon. She referenced a recent example where Which? listed 10 Downing Street as a holiday rental on Booking.com, a spoof that the platform failed to detect. Cereda stated, “It’s time for the prime minister to call on Ofcom to use the online safety act to crack down.” Booking.com responded by explaining that the spoof listing was never fully live and the platform’s automatic fraud controls did not engage properly because the listing was only visible during a 20-minute window for Which?’s testing. A government spokesperson emphasized the responsibility of online platforms under the Online Safety Act to prevent and remove fraudulent content, warning that platforms face penalties and strong regulator action if they fail to protect users. Booking.com reiterated that all affected fraudulent listings were removed and affected customers were contacted and supported based on their individual situations

Read the full article from The BBC here: Read More