---
title: "Rental Scammers Now Hijack Real Booking.com Listings, and A.I. Is Not the Main Tool"
description: "After Madrid, London, Paris and a Tuscan castle, the record points to stolen hotel logins, slow takedowns and official data that lag behind."
author: "rews special report"
published: 2026-10-08T16:16:31Z
modified: 2026-10-09T06:37:39Z
url: https://rews.cc/a/rental-scammers-now-hijack-real-booking-com-listings-and-a-i-1dc235
language: en
type: special report
publisher: "Rews (https://rews.cc)"
---

# Rental Scammers Now Hijack Real Booking.com Listings, and A.I. Is Not the Main Tool

*After Madrid, London, Paris and a Tuscan castle, the record points to stolen hotel logins, slow takedowns and official data that lag behind.*

Special report · By rews special report · October 8, 2026 · https://rews.cc/a/rental-scammers-now-hijack-real-booking-com-listings-and-a-i-1dc235

## In brief

- More than 800 people paid 90 to 180 euros a night for a Madrid flat on Booking.com that did not exist, the building’s caretaker counted
- Similar hijacked listings stranded guests in Siena and Rome, London and Paris between May and September
- Microsoft and Sekoia traced the account takeovers to malware planted on hotel staff computers; logins sold for $5 to $5,000
- U.K. holiday fraud losses fell to £11.2 million in 2024, while Spain’s recorded online fraud rose 4.3% in 2025
- An MEP plans to ask the European Commission whether Booking.com breached the Digital Services Act

For six days this month, travelers holding paid reservations for an apartment at 19 Menéndez Pelayo in Madrid arrived with their luggage at a residential building and found a sign on the door telling them that the place they had booked on Booking.com did not exist and that they should file a report with the National Police.

More than 800 people paid for that apartment, according to a count kept by Cris Bellón, the building’s caretaker, [El País reported](https://english.elpais.com/international/2026-10-08/the-vacation-rental-scam-taking-place-in-a-madrid-apartment-near-maricarmens-home.html). Most had booked a single night at the last minute, paying 90 to 180 euros, for a 53-square-meter flat that advertised parking, a spa, free airport transfers and “a very good breakfast.” Booking.com removed the listing on Oct. 7 and told the trade publication [Hosteltur](https://www.hosteltur.com/179124_bookingcom-elimina-el-anuncio-del-falso-piso-turistico-en-madrid-tras-el-hackeo-a-un-anunciante.html) that it had been an incident affecting “one of our partners.”

Madrid was the latest of at least four such cases in Western Europe since May. A castle estate in Tuscany, a pub and a parliamentary office block in London, and apartment buildings near the Eiffel Tower all drew crowds of guests with bookings for rooms that were never there. In every case with a documented cause, the listing was a real host’s account taken over with stolen credentials, not a page invented from nothing.

Artificial intelligence sits at the edges of these schemes: cleaner phishing messages, a few generated photos and, in one case, Booking.com’s own A.I. assistant vouching for a fake. Whether the problem is growing is harder to say. Britain’s official holiday fraud losses fell in 2024, Spain’s recorded online fraud kept rising, and no government series yet covers the cases of this year.

## Six days in Retiro

The people on the sidewalk on Tuesday night included a Nigerian family on their way to Milan, a Moroccan family with a baby, a couple on a business trip and two retirees from Ecuador. A woman who gave her name as Laura said she had paid 200 euros for three nights because it was “the most affordable option in the area.” “It’s deplorable. We have no other options,” she told El País.

The listing carried a score of 7.7 out of 10 and more than 700 reviews. The tech site [Xataka](https://www.xataka.com/magnet/a-300-metros-casa-maricarmen-hay-increible-fraude-turistico-800-personas-afectadas) recorded the score as 7.5 and reported that the photos were stolen, with “a couple” made with A.I. Ms. Bellón estimated that 90 percent of the victims were foreigners. One review praised the location as being “smack in the Ría de Ferrol,” an estuary in Galicia about 600 kilometers (372 miles) from Madrid.

That review is a clue. A page built from scratch would not carry praise for a coastline at the other end of Spain. A page taken over from a real host somewhere else would, along with that host’s score and history, which fits Booking.com’s account that a partner was hacked.

El País tried repeatedly to reach Booking.com by phone and got A.I. agents. Booking.com later told Hosteltur that it had looked for alternatives and offered rooms elsewhere “whenever possible.” The building is a few minutes’ walk from the home of Maricarmen Abascal, whose eviction at 87 set off housing protests across Spain and who [died this week](https://rews.cc/a/maricarmen-abascal-evicted-at-87-from-her-madrid-flat-dies-b-db1096). The consumer group OCU said platforms that profit from bookings “cannot limit themselves to acting as mere intermediaries,” [Gacetín Madrid](https://gacetinmadrid.com/2026/10/08/denuncian-estafa-alojamiento-turistico-inexistente-retiro-ocu-controles/) reported.

## Four cities, one method

The Castello di Selvole, a wine estate near Siena run by Guido and Nobuko Busetto, found out in early May, when guests began writing to ask whether it was in Tuscany or in Rome. Someone had placed a “dream apartment” near the Colosseum on top of the estate’s Booking.com page. At least 200 tourists were defrauded, and the scheme took in about 224,000 euros in June, 140,000 in July and 13,000 in early August, [Il Fatto Quotidiano](https://www.ilfattoquotidiano.it/2026/08/06/booking-hackerato-agriturismo-siena-truffa-notizie/8471915/) reported. Booking.com’s security team replied only at the end of June, citing suspicious activity from an unknown external device. The couple said the platform then billed them commissions on the fake bookings, 67,000 euros for June and 41,000 for July. The same paper said 90 families had been sold holidays at a nonexistent residence in Cesenatico by the same method.

In London, the consumer group Which? [reported on Sept. 25](https://www.which.co.uk/news/article/houses-of-parliament-used-in-new-booking.com-scam-ad7VC5Q62sDa) that “Apartments near Big Ben” had been listed at the address of Portcullis House, part of the House of Commons estate, where armed guards turned guests away. Tony Walker was charged £243 for three nights. One family drove from Manchester and spent the night in their car with four children. A second listing, “The London Crown,” sent people to The Liberty Bounds, a Wetherspoons pub near Tower Bridge, where one reviewer said staff were turning away about 20 victims a day.

Both London listings came from a genuine Somerset cottage owner’s account, Which? found, and the fake page’s web address still named a Somerset village. Wetherspoons reported the scam to Booking.com on Aug. 10. Guests still held bookings into early September, the page had more than 250 angry reviews, and it sat in Booking.com’s Preferred Plus program, whose members pay 23 percent commission instead of 15 percent. When a Which? researcher asked Dot, Booking.com’s A.I. assistant, whether The London Crown was a scam, it described a legitimate property with free Wi-Fi and parking. The pub chain said in a statement to Which?:

In Paris, Le Parisien reported on Sept. 22 that it had found about 20 fraudulent listings over six weeks, including one near the Eiffel Tower rated 9.3 out of 10, according to [Journal du Geek](https://www.journaldugeek.com/2026/09/25/logements-fantomes-une-nouvelle-arnaque-sur-booking-com-prend-de-lampleur-en-france/), which relayed the findings. A building concierge told France 2 she saw 90 to 150 people a day arrive with suitcases, [Boursorama](https://www.boursorama.com/budget/actualites/entre-90-et-150-personnes-avec-leurs-valises-apres-avoir-reserve-sur-booking-com-ils-se-retrouvent-devant-un-logement-fantome-f8524aecb1b2b99f7c5a4c1091047669) reported. Pascal Mafait, who heads Booking.com’s fraud department, told Le Parisien that “what happened in Paris should not have happened,” according to [Le Tribunal du Net](https://www.letribunaldunet.fr/voyage/booking-faux-appartements-paris-alerte-vacances-hiver.html).

## An older scheme

Fake accommodation is not new. In 2018, Britain’s national fraud reporting center said accommodation bookings made up 38 percent of the holiday fraud reported to it in 2017, behind airline tickets at 47 percent, according to [Action Fraud](https://www.actionfraud.police.uk/news/action-fraud-reports-show-6-7-million-lost-to-holiday-booking-fraud). Lloyds Bank warned in [April 2024](https://www.lloydsbankinggroup.com/media/press-releases/2024/lloyds-bank-2024/lloyds-bank-warns-holidaymakers-on-scams.html) that some victims turned up with their luggage to find the address was fake or belonged to someone else’s home.

What changed was the target. Booking.com fraud has been discussed heavily on Russian-speaking criminal forums since 2022, according to the French security firm Sekoia, and Microsoft said a group it calls Storm-1865 used Booking-themed lures against hotel guests in 2023. Action Fraud said in January 2025 that it had received 532 reports and £370,000 in losses between June 2023 and September 2024 from people contacted through hijacked Booking.com hotel accounts, a [local council’s repost of the warning](https://www.broughton-astley.gov.uk/news/2025/01/bookingcom-users-targeted-with-scam-messages) shows.

Airbnb took a different path. In its [2023 fall update](https://news.airbnb.com/airbnb-2023-fall-update), the company said it had blocked 157,000 fake listings that year and removed 59,000 more, and it began verifying listings in its five largest markets, with hosts confirming their location by GPS from inside the property. Brian Chesky, the chief executive, told The Associated Press that the biggest risk from fake listings was to the company’s reputation.

Booking.com’s onboarding drew sharper criticism. Which? created a holiday-home listing on the site in under 15 minutes, and Trevor Baker, a senior researcher at the group, said Vrbo and Airbnb had both asked for ID, [Euronews reported](https://www.euronews.com/2025/12/23/fake-listings-and-phishing-emails-how-travellers-have-lost-hundreds-to-bookingcom-scams) in December 2025. Mr. Baker said:

> We didn’t need to provide proof of who we were.
>
> — Trevor Baker, senior researcher at Which?, [euronews.com](https://www.euronews.com/2025/12/23/fake-listings-and-phishing-emails-how-travellers-have-lost-hundreds-to-bookingcom-scams)

This summer, Which? went further and listed 10 Downing Street as a holiday let.

## How the logins are stolen

On March 13, 2025, [Microsoft Threat Intelligence](https://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/) described a campaign that began in December 2024. Hotel staff received emails posing as Booking.com, about bad reviews or guest requests, which led to a fake CAPTCHA page that told them to paste and run a command. The command installed password-stealing malware, including Lumma Stealer, XWorm and VenomRAT. Booking.com said its own systems had not been breached.

Sekoia published its “I Paid Twice” report on Nov. 6, 2025, named for the subject line of an email from a guest who paid once to his hotel and again to a criminal. The campaign had run since at least April 2025. Stolen Booking.com logins sold for $5 to $5,000 each, and a buyer calling himself “moderator\_booking” claimed his team had earned more than $20 million, [according to the report](https://www.sekoia.com/blog/phishing-campaigns-i-paid-twice-targeting-booking-com-hotels-and-customers). The researchers concluded:

> Services offered on cybercrime forums have substantially facilitated these campaigns
>
> — Sekoia.io threat researchers, in their November 2025 report, [sekoia.com](https://www.sekoia.com/blog/phishing-campaigns-i-paid-twice-targeting-booking-com-hotels-and-customers)

On April 13 this year, Booking.com confirmed that unauthorized parties had accessed customers’ names, email addresses, phone numbers and booking details, [TechCrunch reported](https://techcrunch.com/2026/04/13/booking-com-confirms-hackers-accessed-customers-data/). [Malwarebytes](https://www.malwarebytes.com/blog/data-breaches/2026/04/booking-com-breach-gives-scammers-what-they-need-to-target-guests) said message histories between guests and hosts were exposed as well. The company reset reservation PINs and has not said how many people were affected.

Researchers at Gen, the company behind Norton, [published on May 28](https://www.gendigital.com/blog/insights/research/reservation-hijack-scams-target-travelers) what they called a conservative count: 350 compromised properties in 50 countries, led by Germany with 49, France with 35 and Britain with 31. Spain had 20. Together the properties hold about 82,000 guests at a time, which the researchers translated into roughly six million stays a year whose booking data could be exposed. They wrote that the figure did not mean six million people had been scammed.

Luis Corrons and Martin Chlumecký, the authors, were plain about the limits of what they could see:

> 350 is not the size of the problem. It is the part we could see clearly.
>
> — Luis Corrons and Martin Chlumecký, researchers at Gen, [gendigital.com](https://www.gendigital.com/blog/insights/research/reservation-hijack-scams-target-travelers)

## What the numbers show

The British series, the longest public one for holiday fraud, does not show a surge. Victims reported losing £15,319,057 in the 2022-23 financial year. They lost £12.3 million across 6,640 reports in 2023 and £11,183,957 across 6,066 reports in 2024, with the average loss steady at about £1,850, according to the [last Action Fraud release](https://www.actionfraud.police.uk/news/holiday_fraud) in February 2025. More than half the reports mentioned social media. Report Fraud replaced Action Fraud on Dec. 4, 2025, and has not published holiday figures for last year.

Bank data point the other way on severity. Lloyds said in 2024 that holiday scams had risen 7 percent, with an average loss of £765, and in 2025 that the average loss had climbed 21 percent to £928, [NationalWorld reported](https://www.nationalworld.com/travel/lloyds-alerts-hopeful-holidaymakers-as-holiday-scam-victims-lose-21-more-than-last-year-ps928-on-average-5072969).

Spain does not break out rental fraud, but its police count of online fraud has climbed for a decade: 70,178 cases in 2016, 412,850 in 2024 and 430,493 in 2025, a rise of 4.3 percent in the last year, according to the Interior Ministry’s [annual crime report](https://www.interior.gob.es/opencms/export/sites/default/.galleries/galeria-de-prensa/documentos-y-multimedia/balances-e-informes/2025/Balance-de-Criminalidad_Cuarto_Trimestre_2025.pdf). The ministry’s separate cybercrime report, [released July 10](https://www.lamoncloa.gob.es/serviciosdeprensa/notasprensa/interior/Paginas/2026/100726-interior-ciberdelitos.aspx), counted 383,285 victims of cybercrime, up 9.3 percent.

In the United States, people reported nearly 65,000 rental scams to the Federal Trade Commission from January 2020 through June 2025, with about $65 million in losses and a median loss of $1,000, [the agency said](https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/12/rental-scams-hit-home-65-million-reported-losses) in December 2025. About half began with a fake ad on Facebook. The commission cited a study finding that only 4.8 percent of fraud victims complain to a government agency or the Better Business Bureau.

Booking.com’s own figures depend on the telling. The company said it blocked about 1.5 million fake phishing reservations in 2023 and 250,000 in 2024, which it read as a sign that deterrence was working, according to [BearingPoint](https://bearingpoint.services/it-security/en/know-how/news-phishing-alert-at-booking/), citing the German outlet Heise. For the past year, El País reported 14 million blocked phishing attempts (its English edition printed the year as 2015), while [Reportur](https://www.reportur.com/agencias/2026/09/10/booking-referente-para-fraudes-disparados-al-suplantar-su-imagen/) gave 14 million fraudulent transaction attempts and 26,000 compromised accounts. Le Parisien’s version had 26,000 scam attempts blocked in 2025 by a team of more than 130 specialists.

Read together, the record does not show holiday fraud exploding in the official counts through 2024. It shows general online fraud rising in Spain and the United States, and a different kind of case this year. In Madrid, Paris, London and Siena, a single hijacked page took money from hundreds of people over weeks. The lag between first complaint and removal ran from six days in Madrid to more than six weeks in London and Siena.

## Where A.I. fits

The strongest case that A.I. is driving the trend came from Booking.com itself. Marnie Wilking, the company’s chief information security officer, told the Collision conference in Toronto in June 2024 that phishing had risen by 500 to 900 percent over about 18 months, [Silicon UK reported](https://www.silicon.co.uk/cloud/ai/booking-com-scam-surge-ai-569105).

> Of course, we’ve had phishing since the dawn of email, but the uptick started shortly after ChatGPT got launched
>
> — Marnie Wilking, chief information security officer of Booking.com, [silicon.co.uk](https://www.silicon.co.uk/cloud/ai/booking-com-scam-surge-ai-569105)

That figure has since been repeated as a 900 percent rise in travel scams, including in a December 2025 alert from the U.S. Congress’s Joint Economic Committee. In her fuller remarks to Agence France-Presse, Ms. Wilking described the increase as “throughout all industries,” [The Malay Mail reported](https://malaymail.com/news/life/2024/06/20/bookingcom-sounds-alarm-on-ai-enabled-travel-scams/140542). It was a statement about phishing in general, not a count of travel fraud.

There is other evidence for an A.I. role. Le Tribunal du Net reported that the Paris attack involved artificial intelligence tools, relaying Mr. Mafait’s interview. Le Parisien posted its own fake listings on Airbnb using stock photos and A.I.-generated images. In a survey for Airbnb and the British group Get Safe Online [published in February 2025](https://news.airbnb.com/en-uk/airbnb-and-get-safe-online-raise-awareness-of-holiday-scams-this-easter), 34 percent of British adults took A.I.-generated property images for real and 27 percent were not sure.

The evidence against A.I. as the engine is in the cases themselves. Each 2026 listing was exposed by something inherited from a real host: a review about Ferrol, a Rome apartment that mentioned Chianti vineyards, a London page whose address named a Somerset village. The fraud worked because it carried genuine reviews and booking history, which only a stolen login provides. The documented thefts, from Microsoft’s Storm-1865 report to Sekoia’s, ran on malware and tricked hotel staff.

A.I. also appears on the defenders’ side, with mixed results. Gen used A.I.-assisted analysis, checked by people, to link its 350 properties. A Booking.com spokesperson told Euronews the company uses “the latest AI and machine-learning techniques” to block suspicious activity. Its assistant, Dot, called The London Crown legitimate.

## What comes next

Which? said it would send its findings to Ofcom and wants the British regulator to examine whether Booking.com is meeting its duties under the Online Safety Act. In Spain, OCU has asked for faster refund procedures when a scam is evident and for platforms to share in compensating victims. Booking.com has warned travelers to be careful over the winter holidays.

Laura Ballarín, a Spanish Socialist member of the European Parliament who coordinates her group on the internal market and consumer protection committee, said she would submit a written question to the European Commission over the Madrid listing, [Reportur](https://www.reportur.com/agencias/2026/10/08/booking-nueva-estafa-a-cientos-de-turistas-en-madrid-por-falso-hotel/) and Hosteltur reported. She wants the commission to examine whether Booking.com breached as many as four articles of the Digital Services Act on verifying hosts’ identities and reducing fraud risks to consumers.

## See also

- [FTC Data Spotlight: Rental scams (PDF)](https://www.ftc.gov/system/files/ftc_gov/pdf/rental-scams-spotlight-2025.pdf) — ftc.gov · The full U.S. rental scam analysis with age and platform breakdowns
- [Reservation Hijack Scam, Norton](https://us.norton.com/blog/online-scams/reservation-hijacking-scam) — us.norton.com · A consumer guide to the scam that quotes real booking details back to guests
- [Booking.com Warns Travelers of Reservation Data Breach, Skift](https://skift.com/2026/04/13/booking-com-hacked-data-breach-reservations/) — skift.com · Trade coverage of the April 2026 breach and what the company would not disclose
- [B2B2C supply chain attack on hotels, DomainTools](https://dti.domaintools.com/securitysnacks/b2b2c-supply-chain-attack-hotels-booking-accounts-compromised-to-target-customers) — dti.domaintools.com · Tracks nearly 1,000 fake booking domains registered since May 2025
- [La Nazione: the Castello di Selvole owners' account](https://www.lanazione.it/siena/cronaca/ci-hanno-rubato-il-profilo-booking-e-ora-ci-chiedono-140mila-euro-lincubo-dei-proprietari-del-castello-di-selvole-ifid38p7) — lanazione.it · The Tuscan hosts describe losing their Booking.com profile and the commission bill
- [Booking.com accused of ignoring fake Wetherspoons listing, RTE](https://www.rte.ie/news/business/2026/0925/1592936-booking-accused-of-ignoring-fake-listings/) — rte.ie · Irish broadcaster's account of the London pub and Parliament listings
- [Rental and housing scams, FTC consumer advice](https://consumer.ftc.gov/all-scams/rental-housing-scams) — consumer.ftc.gov · Official U.S. guidance on spotting fake rental listings
- [Airbnb removes 59,000 fake listings, The Columbian (AP)](https://www.columbian.com/news/2023/sep/20/airbnb-says-its-cracking-down-on-fake-listings-and-has-removed-59000-of-them-this-year/) — columbian.com · The 2023 AP report on Airbnb's listing verification push
