Skip to main content

Company intelligence

Booking cybersecurity incidents and threat signals

booking.com

Booking logo

This company page brings together public reporting currently associated with Booking. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 22, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Booking. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Booking

Booking logoUse of stolen credentials or exploit
High

Booking.com Confirms Data Leak Exposing Customer Booking Information

New Booking.com data breach forces reservation PIN resets Booking.com is - as the name suggests - a website that allows users to book travel including flights, car rentals, hotels, and more. They are one of the largest such sites. Users have reported getting emails from noreply@booking.com informing them of a "cybersecurity incident" that may have exposed full names, email addresses, postal addresses, phone numbers, and communication with property providers. Booking.com is not being transparent about the number of users impacted, but said all users will be individually notified. They are also resetting user reservation PINs out of caution. European Gym giant Basic-Fit data breach affects 1 million members Basic-Fit is one of the largest gym chains in Europe with over 1700 clubs and 430 franchises in 12 countries. In a disclosure published on their website, they have announced a cyberattack that impacted full name, physical address, email address, phone number, date of birth, bank account details, and "other membership information." It appears to have impacted about 1 million members. McGraw-Hill confirms data breach following extortion threat McGraw-Hill is an education company that offers textbooks, online portals, and systems for K-12 schools and universities. This attack appears to have come from a misconfigured Salesforce page. McGraw-Hill says the data exposed was "limited and non-sensitive," but the attacker claims to have 45 million records containing personally identifiable information. Crypto-exchange Kraken extorted by hackers after insider breach Kraken says that attackers are threatening to release a video that shows internal systems that host client data. The article is a bit unclear but it does seem that the attackers were showing that they had actual access to the data, though it seems it was through inside employees and not via a technical hack (such as a vulnerability). Kraken said that funds are safe and employees have been terminated. They say the breach was limited to about 2,000 customers but have not shared what information was impacted. Fashion retailer Express left customers’ personal data and order details exposed to the internet This was a flaw appears to have been an "insecure direct object reference" vulnerability - where simply tweaking the web address is enough to pull up other pages you may not necessarily have been meant to see. In this case a researcher was able to access other users' order confirmation pages, which included names, phone numbers, email addresses; postal, billing, and delivery addresses; order details including the items that a customer purchased, and partial payment card information including the card type and the last four-digits. Fiverr Exposes Private Information of its Users Publicly on Google Search Results From our own staff writer Fria, a researcher on Hacker News claimed that Fiverr - a freelancer job board - was exposing sensitive personal documents such as tax forms containing Social Security Numbers. The data could easily be found by searching site:fiverr-res.cloudinary.com [keywords of choice, such as "form 1040" or a name] on most search engines including Google and even DuckDuckGo. According to our internal news chat, the data itself does appear to have been secured. Privacy Guides Executive Director Jonah Aragon was unable to reproduce the results on Google, but both Jonah and Fria were able to find the results on DuckDuckGo, though they no longer linked to a valid address. Russian-linked hackers escalate attacks on European energy infrastructure Microsoft Patch Tuesday fixes 167 flaws, including two zero-days Rockstar Games data breach linked to third-party SaaS compromise Basic-Fit breach exposes data of one million members Booking.com breach exposes customer booking data Sweden has revealed that Russian state-linked hackers attempted to disrupt operations at a thermal power plant in early 2025, marking another escalation in attacks against European critical infrastructure. While the intrusion was ultimately unsuccessful due to built-in protections, officials have warned that the nature of these threats is shifting. According to Civil Defence Minister Carl-Oskar Bohlin, groups previously associated with low-level disruption are now attempting far more destructive cyberattacks. This incident reflects a broader pattern of increasingly aggressive activity targeting energy and utility systems. Similar operations have been reported across Europe, including attempts to interfere with Poland’s power grid and a breach of a Norwegian dam, where floodgates were briefly opened. Ukraine has also faced repeated attacks on its energy infrastructure in recent years. The trend highlights a growing convergence between cyber operations and real-world disruption, reinforcing the need for stronger resilience across critical national infrastructure. Microsoft’s April 2026 Patch Tuesday delivered security updates for 167 vulnerabilities, including two zero-day flaws and eight rated Critical. The majority of issues centre on elevation of privilege vulnerabilities, alongside 20 remote code execution bugs that could enable attackers to take control of affected systems. Of particular concern is an actively exploited zero-day, CVE-2026-32201, impacting SharePoint Server and allowing spoofing attacks that could expose or manipulate sensitive data. A second zero-day, CVE-2026-33825, affects Microsoft Defender and enables privilege escalation to SYSTEM level, significantly increasing the risk of full system compromise. Multiple critical vulnerabilities were also identified across Microsoft Office, including Word and Excel, where malicious documents or even preview pane interactions could trigger exploitation. This makes email-based attack vectors especially dangerous. The update highlights the continued scale and complexity of patch management, with organisations urged to prioritise updates across SharePoint, Defender, and Office to reduce exposure to active threats. Rockstar Games has confirmed a data breach following a wider security incident involving Anodot, with the ShinyHunters gang now leaking what it claims are 78.6 million records. The attackers allege the data was accessed via compromised authentication tokens tied to Snowflake environments, highlighting the growing risk posed by third-party SaaS integrations. According to Rockstar, the breach involved a limited amount of non-material company information and has not impacted operations or players. However, the leaked datasets reportedly include internal analytics tied to Grand Theft Auto Online and Red Dead Online, such as revenue metrics, player behaviour tracking, and support system data.

Booking

FAQ

Questions about Booking cybersecurity reporting

What does the Booking page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Booking.

Does every mention of Booking appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.