The Daily Newsstand · Free, Always
Friday, October 9, 2026

Beware of scams impersonating travel platforms, $185,000 lost since January: Police

Translate

SINGAPORE – Travellers are being targeted by convincing phishing messages that contain details of their actual accommodation bookings, including their travel dates and destinations, with at least 148 cases reported since January.

The police said in a statement that victims would receive messages, mostly through WhatsApp, or emails from scammers impersonating hotels or hotel booking platforms, prompting them to verify their card details or confirm their upcoming accommodation bookings.

In some instances, the messages or emails contained legitimate booking details, lending credibility to the scam, the police added.

Victims would then be instructed to access a phishing link to secure their bookings by providing their bank card information on the webpage and authorising the resulting transactions.

The police said that victims would only realise they had been scammed after unauthorised transactions were made to their bank cards, and upon checking in with the hotel directly.

To date, the total losses from these scams have amounted to at least $185,000.

Similar to the methods mentioned in the police advisory, a Singaporean man said in an Instagram post on Sept 12 that he received a WhatsApp message about his upcoming Booking.com reservation requiring “one final action”.

The Singaporean man, who booked his trip through Booking.com, was informed that the payment system has not received any final confirmation.

He was directed to a website, which displayed details of his actual reservations, including the date and location of his accommodation. At the bottom of the page, the man was prompted to enter his payment details.

While he did not enter his payment information as instructed, he subsequently warned others about the scam. His post has since garnered over a million views.

In a response to media queries, Booking.com said it is aware of phishing attempts that were carried out through WhatsApp.

“Booking.com will never ask customers to provide credit card details via text, WhatsApp, email or phone call. We will also never ask them to make a bank transfer that differs from the payment policy stated in their booking confirmations,” the travel platform’s spokesperson said in its response on Sept 18.

The spokesperson reminds customers that they should avoid clicking on unfamiliar links or sharing sensitive information, and verify payment requests through the Booking.com app, with the hotel directly or the 24/7 customer service team.

“Anyone who has already shared information or made payment should contact their bank immediately and our customer service team,” the spokesperson said.

Booking.com had suffered a data leak in April, during which unauthorised parties may have accessed information associated with some customer reservations.

Information potentially accessed included customers’ names, booking details, e-mail addresses and phone numbers.

The platform did not provide further details on the scale of the breach, such as the number of customers affected. The spokesperson also confirmed that customers’ financial information and physical addresses were not accessed through Booking.com’s system.

It subsequently said that updated PINs were provided for reservations affected by the unauthorised access, and customers were informed accordingly.

The police advised members of the public to adopt several precautionary measures to avoid falling for scams.

These included downloading the ScamShield app, setting up security features such as two-factor authentication and money lock features for banks and e-wallets, checking for signs of scams with official sources, and informing authorities, family and friends about scams.

For more information on scams, members of the public may also call the 24-hour ScamShield Helpline at 1799, or visit www.scamshield.gov.sg.

View the original on The Straits Times →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.