In Brief: Travel companies face growing cyber risks because stolen booking and contact information can fuel convincing scams, while complex supplier networks expand the number of possible entry points for attackers.
-
Stolen Travel Booking Data Fuels Targeted Phishing and Fraud – Image Credit Unsplash+
Booking Data Can Make Scams More Credible
Cybercriminals targeting travel companies may find customer booking information more useful than payment-card data in some cases. Details such as a hotel name, travel date, vehicle registration, airport service booking or business contact can help criminals create messages that appear legitimate.
Recent incidents involving Manchester Airports Group, Booking.com and BCD Travel have illustrated how customer and business information can be used in phishing, impersonation and extortion attempts. The information may not include bank details, but it can allow criminals to tailor messages to specific travelers or employees.
Cybersecurity expert Boštjan Koželj said many attacks do not involve sophisticated technical methods. Instead, attackers often steal passwords, persuade users to share personal information, or use fraudulent links that lead to fake login pages. Once they capture credentials, attackers may access customer information, operational systems or legitimate company accounts.
Airport and Hotel Information Can Be Exploited
Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, disclosed in August that an unauthorized third party had accessed customer information connected to car parking, airport lounges, Fast Track security services and Wi-Fi registrations.
The information included email addresses, telephone numbers, vehicle registrations and postcodes. MAG said the affected system did not contain bank or payment information. However, cybersecurity specialists say non-financial information can still be used to make fraud attempts appear authentic.
Dray Agha, senior manager of tactical response at cybersecurity company Huntress, said a criminal who knows a traveler’s vehicle registration could send a fraudulent message claiming that the person had received a parking penalty. The detail could make recipients more likely to click a link or submit payment.
Booking.com confirmed in April that unauthorized parties had accessed data including names, email addresses, telephone numbers and reservation details. Researchers at Gen Digital later identified reservation-hijacking scams affecting more than 350 accommodation properties across more than 50 countries. In those cases, criminals used genuine booking information to send messages appearing to come from hotels.
Real Breaches Can Support Later Fraud Claims
Information linked to a breach can remain valuable after the initial incident. After BCD Travel disclosed suspicious activity in May, extortion emails later circulated claiming to be based on a “BCD Travel database.” The messages did not demonstrate that their senders had accessed BCD’s systems, but the reports of suspicious activity could have made the claims more believable.
Riskified, which analyzes travel transactions, has reported increased use of legitimate identities, known devices and compromised travel-platform accounts by fraudsters. Such information can help criminals imitate standard customer behavior and evade basic fraud checks.
Agha said attackers may not know immediately which data will be useful. Information that appears routine can become valuable when combined with other details, particularly in identity fraud and targeted phishing schemes.
Suppliers and Partners Increase Exposure
Travel transactions often involve multiple companies and technical systems. A single reservation may pass through an airline, hotel, online travel agency, global distribution system, property management system, payment provider, channel manager and other suppliers.
This interconnected structure creates more potential routes into sensitive systems. Koželj said attackers often target a company’s weaker suppliers rather than attempting to penetrate its best-protected systems directly.
He cited the 2025 Qantas data breach, which occurred through a third-party platform used by a contact center contractor. The case reflected a wider challenge for travel companies: they may have limited visibility into the security practices of vendors that process or access their data.
Krasimir Simonski, a cybersecurity specialist and former Bulgarian government official, said supply-chain security is difficult because organizations have less control over products and systems managed by others. If a supplier is compromised, the consequences can extend to customers and users further along the chain.
Access Controls Are a Central Concern
Experts said the principal risk is not simply the number of technology partners but the degree of trust granted to them. Companies may not have a complete record of which suppliers can access sensitive systems, how long that access remains active or whether it can be quickly removed during an incident.
Business-to-business application programming interfaces, including airline New Distribution Capability connections and hotel channel-management services, can increase the importance of access management. Poorly protected connections may allow attackers to move between systems or obtain data without directly targeting a travel company’s main network.
Agha compared third-party compromise to a problem originating upstream from an organization’s main defenses. Investigations can show that a trusted vendor, rather than the directly targeted company, was the original point of entry.
AI Increases the Scale of Existing Tactics
Artificial intelligence is making familiar types of fraud faster and easier to scale, according to the experts. Generative AI can help attackers produce grammatically correct phishing messages in multiple languages and adapt them to genuine booking information.
Voice-cloning technology may also be used to impersonate hotel staff, travel agents or company employees. Agha described AI as a tool that can benefit attackers and defenders alike. While criminals can use it to increase the volume and apparent credibility of scams, security teams can use automated systems to identify unusual account activity and other indicators of compromise.
Simonski said agentic AI could speed up attacks by letting systems select tools, plan actions, and adjust their approach with limited human direction. A highly connected travel environment could identify weak passwords, excessive permissions, and insufficiently monitored supplier connections more quickly.
Experts Emphasize Basic Security Measures
Despite the increased use of AI, the cybersecurity specialists said fundamental controls remain the most effective defenses. These include multifactor authentication, prompt software patching, limited user permissions, employee training, continuous monitoring and tested incident-response plans.
Simonski estimated that most incidents he encounters stem from basic cybersecurity failures, including weak password practices and excessive trust in users or suppliers.
Koželj recommended that travel companies maintain an inventory of all systems and vendors handling customer data. Third-party access should be routed through company-controlled authentication systems, permissions should be restricted, and unusual data exports should be monitored.
Zero-trust practices can add further protections by requiring users, devices and suppliers to repeatedly verify their authorization. Measures can include short-lived access tokens, continuous authentication for APIs and network segmentation.
Travel companies can also identify vulnerabilities through internal testing and public bug-bounty programs. Agoda announced a HackerOne program in June that allows approved security researchers to test specified elements of its website, mobile application and APIs.
However, experts said such programs cannot eliminate social engineering or supplier-related risks. Companies must be prepared to detect and respond when a partner is compromised, not only when their own systems are directly attacked.
Discover more at PhocusWire.


