Booking.com says typo bug can give strangers access to your whole trip

Fingers typing on a computer keyboard.
(Image credit: Shutterstock)

  • Booking.com apparently links reservations to accounts without any verification
  • User finds typing the wrong email address could link your vacation to another account
  • The company did not remove a false booking from one user’s account

Travellers using Booking.com to pay for accommodation and transport have been warned about a simple typo bug that could see them share their private trip details with strangers, giving them access to sensitive information and even allowing them to take control over bookings.

The issue came to light when a Booking.com user, named as Alfie, received an unexpected email confirming a trip that he hadn’t booked.

Although he exercised caution by not following links on the email, suspecting it was a phishing scam, the mysterious booking had been added to his account, confirming suspicions that the email was indeed from Booking.com.

Watch out for this Booking.com bug

After failing to receive an explanation from the company’s support team, Alfie shared the story with Ars Technica which pressed Booking.com for answers.

It was later revealed the problem occurred when another user had entered Alfie’s email address, presumably by accident, causing the reservation to link to his account. Booking.com has therefore stated the incident is neither a “system glitch” nor a “security breach,” however we now have questions about the robustness of Booking.com’s system.

Booking.com said (via Ars Technica): “Following our investigation, we found that the issue occurred due to a customer input error during the reservation process, where he inadvertently entered an incorrect email address. That email address, however, belonged to another Booking.com customer which caused the reservation to be linked to their account.”

Alfie’s experience highlights a worrying loophole where Booking.com’s system automatically adds bookings to accounts via the email address provided, without any further verification, making it easy to inadvertently share private information with others and lose your own booking.

Although the chances of typing a completely different email address are pretty slim, a single misplaced letter could direct the booking to another closely related email address.

Moreover, Booking.com declined to remove the trip from Alfie’s account, stating that it would be a violation of the privacy of the user who actually booked the trip.

You might also like

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Password
Millions of airline customers possibly affected by OAuth security flaw
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
Hands typing on a keyboard surrounded by security icons
Your passwords aren't the key to protecting your online identity, your email address is
Suitcase next to a bed in a hotel
Millions of hotel users see personal info checked out in huge data leak
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection