Last updated 2 weeks ago
Booking.com, a Netherlands-based online travel agency, was targeted in a phishing campaign affecting its partner accommodations in Japan during May 2026. The attack was publicly disclosed in July 2026, though the exact discovery date and number of affected partners or records are not specified. The incident involved phishing emails sent to hotel partners, leading to the deployment of blockchain-hosted malware.
The attack chain began with phishing emails directed at Booking.com partner accommodations in Japan. The emails contained links or attachments that, when interacted with, led to the execution of malware hosted on blockchain infrastructure. The specific data types compromised, if any, are not detailed in the article. No threat actor group is attributed, and no CVEs or MITRE ATT&CK techniques are mentioned.
No post-incident developments such as regulatory actions, litigation, ransom payments, or containment milestones are reported in the article.
Phishing emails sent to partner accommodations in Japan, leading to blockchain-hosted malware
Booking.com's reliance on partner accommodations without robust phishing-resistant authentication or security awareness training for partners likely contributed to the success of this campaign. The use of blockchain to host malware highlights the need for advanced threat detection capabilities that can identify novel hosting methods. Organizations in the travel sector should implement multi-factor authentication for partner portals and conduct regular phishing simulations to reduce the risk of credential compromise and malware deployment.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector