Booking.com data breach warning · Updated 22 July 2026

Booking.com reservation data exposed. WhatsApp scams followed.

Booking.com confirmed unauthorized access to reservation information. The exposed data enables scammers to send highly convincing messages using real guest and booking details.

This was not caused by Mahaloka Valley. The fraudulent message was not sent by us, and there is no evidence our website, WhatsApp, email, or internal systems were breached.

WARNING / PHISHING DANGER Warning illustration of a smartphone message, alert triangle, and protective shield
Real reservation details can make a fraudulent message look genuine. Accuracy is not proof of authenticity.

Stop before you click

Do not pay, verify a card, or share banking information from a WhatsApp link

A message can contain your correct guest name, hotel name, booking dates, and reservation number and still be fraudulent. Correct information does not prove a message is legitimate.

01NOT SENT BY MAHALOKA VALLEY
02NO EVIDENCE MAHALOKA VALLEY’S SYSTEMS WERE BREACHED
03BOOKING.COM RESERVATION DATA ENABLED THIS SCAM

Evidence

See how exposed reservation details are used

The guest evidence and independent reporting below show why a message can appear authentic even when it is fraudulent.

Actual fraudulent message

WhatsApp scam sent to a Mahaloka Valley guest

Redacted screenshot of a fraudulent WhatsApp message showing scammer phone number plus 55 88 98136 1900 and a fake hotel reservation verification request
Privacy redaction: only the guest’s name and stay dates are blurred. The scammer’s phone number, profile, account information, Mahaloka Valley reference, and scam wording remain visible.

Scammer contact shown: +55 88 98136-1900

Independent reporting

Booking.com confirmed hackers accessed customer data

TechCrunch headline Booking.com confirms hackers accessed customers' data by Lorenzo Franceschi-Bicchierai, published April 13 2026
Headline, publisher, author, and publication date from TechCrunch’s 13 April 2026 report. Click the image or link to read the original reporting.
What the reporting confirms

Booking.com said unauthorized third parties may have accessed personal and reservation information, including data shared with accommodation providers.

What Booking.com confirmed

Unauthorized parties accessed certain reservation information

The exposed information may include guest names, phone numbers, email addresses, hotel details, booking dates, reservation details, and information shared with the property.

This data allows scammers to send extremely convincing WhatsApp messages containing real reservation information. Booking.com was responsible for protecting the reservation information stored and processed through its platform.

Mahaloka Valley’s position

Our systems are not the source identified in this incident

The fraudulent message received by our guest was not sent by Mahaloka Valley. There is no evidence that Mahaloka Valley’s website, WhatsApp, email, or internal systems were breached.

The scam was made possible by reservation information exposed through Booking.com’s security incident. Mahaloka Valley did not authorize the message and did not send the fake payment request.

Why the message looks genuine

Accuracy is not authenticity

Scammers can use correct guest names, hotel names, booking dates, reservation numbers, and other reservation details to make a message feel personal and urgent. They may ask you to “reconfirm” a card, pay a balance, or prevent a cancellation.

Correct guest names, hotel names, dates, and reservation numbers do not prove a message is legitimate.

Fake payment page danger “Card not accepted”

A fake payment page may display this message after it has already collected your card information. Do not keep trying another card.

If you entered card details

Contact your bank immediately

Do not wait for a transaction to appear before protecting your account.

  1. Contact your bank immediately. Tell the bank that your card details were entered on a suspected phishing page.
  2. Block or replace your card. Follow your bank’s instructions and request a new card if advised.
  3. Check for unauthorized transactions. Review your account and report anything unfamiliar to your bank or card provider.
  4. Never share a security code. Never share an OTP, PIN, password, CVV, or banking approval code with anyone who contacts you.

Verify through a trusted channel

Use Mahaloka Valley’s official website or official WhatsApp

Do not use links, phone numbers, or contact details inside a suspicious message. Open our website yourself or contact our official WhatsApp number directly.

Trusted sources

Independent reporting and Booking.com safety guidance

These links open the original sources in a new tab.

WHEN IN DOUBT, STOP. Verify independently before you reply, pay, or share any information.