Cyberattacks: The Security of Flying Below the Radar Versus the Visibility of Major OTAs

Security 21/07/2026
Cybersecurity lock icon on digital circuit board background Cyberattacks: The Security of Flying Below the Radar
Three months later, in the middle of peak season, the effects of the cyberattack that compromised booking data managed by Booking.com last April are now being felt.

Missing or altered reservations, duplicate payments… This is the latest sign of a trend the industry has been watching grow for some time: phishing campaigns targeting guests, fraud involving reservation data, information breaches, and more. This is not an isolated case, and as a hotelier, it is worth paying close attention, because when fraud materializes, it may do so with your property’s name in the email subject line.

The Cyberattack Booking.com Suffered in April 2026


As reported by El Español, the unauthorized access to personal data, phone numbers, email addresses, and reservation details—fortunately excluding financial information—is now resulting in altered reservations, fraudulent payments, and travelers arriving at their accommodations only to find that there is no longer any availability.

What makes these malicious actions so effective is that “the criminal knows real details about the trip.” As Sergio García, manager of technology company i3e, explains in the article, they know where you are staying, when you are traveling, and even the value of the reservation. With that information, they impersonate the hotel or the platform itself and request additional payments or changes to bank account details. The message does not look like a scam; it looks like your hotel.

The worst-case scenario is that the problem is discovered upon arrival at the destination, after hours of travel and in the middle of peak season. Resolving it is complex and costly. In many cases, it is also difficult to determine responsibility, and the affected traveler ends up covering accommodation or transportation expenses while the incident is investigated.

Why Major Platforms Are Always in the Crosshairs


The attacker’s logic is simple: they go where the biggest payoff is. Major OTAs manage enormous volumes of reservations and personal data, and that concentration makes them an extremely valuable target. Millions of trips, names, phone numbers, and payments in one place are a magnet for anyone looking to profit from an attack.

Let us make one thing clear from the outset: this is not about who is more secure. Major platforms invest heavily in protection. It is about where attackers focus their attention and, logically, that focus falls on whoever concentrates the greatest volume.

This is where the direct channel has a quiet advantage: it flies slightly below the radar. It does not concentrate the same potential payoff, the chain of intermediaries is shorter and, most importantly, you control it. Fewer hands handling guest data means a smaller attack surface.

We insist: OTAs remain valuable partners for visibility and are at the forefront of security. The message is not so much “stay away from OTAs” as “do not depend on a single channel, and strengthen the one you do control.” In addition to being profitable, diversification is a form of resilience.

Protecting Traveler Trust Is Now as Critical as Protecting the Business


Guests do not distinguish between technical nuances. If they receive a message under the umbrella of your hotel brand and lose their money, they will see you as responsible. And that is the real cost of these scams:
  • Reputation: Negative reviews, public complaints, and a conversation you no longer control. Rebuilding trust costs far more than the lost reservation.
  • Operations: Discrepancies between the information held by the guest and what appears in your PMS, with an overwhelmed front desk resolving incidents it did not create. In August. With the hotel fully booked.
  • Trust: It is the most difficult asset to recover. One poorly managed case carries more weight than one hundred flawless stays.

What You Can Do (and Recommend to Your Guests)


A large part of the defense comes down to digital hygiene, regardless of where the data breach originated:
  • Secure your access points. Enable two-step verification for both the extranet and corporate email accounts. Use unique, strong passwords and review them regularly.
  • Train your team. Front desk and reservations staff are the first line of defense. They must be able to recognize an email requesting an off-channel payment or a change to bank account details, and understand that when in doubt, they should not act—they should verify.
  • Establish an official channel and communicate it clearly. Define which channels you use to request payments and which ones you do not. Leave no room for ambiguity.
  • Get ahead of the guest. Contacting guests through your official channel within the 48 hours before arrival confirms the reservation and neutralizes the impersonator at the same time. A message as simple as “we will never ask you to make an additional payment by email or through a link” is worth more than any apology afterward.

At Paraty Tech, Security Is the Foundation, Not the Final Layer


For more than 14 years, we have helped over 3,500 hotels increase their direct sales, achieving an average 30% increase in direct bookings. And that direct business is supported by something that is not always visible, but lies at the heart of the way we work: security.

At Paraty Tech, in addition to relying on the best partners, such as Google, we do not purchase security from a catalog. We design it, develop it, and operate it ourselves, using 100% in-house technology created for the hotel industry and fully aligned with our systems architecture. This means we do not inherit vulnerabilities from third-party code, and every improvement we implement for one hotel goes on to protect all the others. Staying one step ahead is the only way to approach this area.

What does that mean in practical terms for your data and your guests’ data:
  • Payments that cannot be stolen. We do not store full card details. Payments are processed through an external gateway in compliance with PCI DSS standards. What is not stored cannot be compromised.
  • Encrypted reservation data. Both at rest and in transit, using TLS 1.2 or higher, with every operation logged for full traceability.
  • Protected access. Two-factor authentication for each user, brute-force attack protection, geolocation controls, and full traceability of who accesses what, when, and from where. We even notify you if one of your passwords appears in a known public data breach.
  • Real-time defense. A proprietary firewall, anti-bot and anti-scraping protection, and denial-of-service attack mitigation to keep your booking engine available and your rates protected.
  • AI-powered forensic response. If your guests experience a phishing attempt, we audit the affected access records and provide you with a complete, time-stamped report very quickly. Knowing who accessed the system, when, and from where makes the difference between responding effectively and being left in the dark.
All of this is carried out in compliance with the GDPR and Spain’s LOPDGDD, and is subject to risk assessments by independent third parties. Because self-assessment alone is not enough.

This is the foundation on which we build the hotel’s direct channel. Every reservation that comes through your direct channels travels through a shorter, better-protected chain. In a context where fraud arrives disguised as your hotel, keeping the conversation in-house, and secure, is worth its weight in gold.

Don't hesitate to contact us to learn more about these and the many other security measures we have in place to safeguard both your property and your guests.
Share: