X

Real Hotel Booking Used in Convincing Phishing Attempt

A Greek lawyer narrowly avoided a phishing scam linked to a real hotel booking, with a fake Booking-style page and card verification request.

  • Lawyer George Linakis narrowly avoids digital fraud following a legitimate hotel reservation.
  • Fraudsters sent a WhatsApp message mimicking a hotel confirmation and directed the victim to a fraudulent portal that mirrored Booking.
  • A missing input field for the One-Time Password (OTP) exposed the trap before funds could be moved.

A hotel booking can be enough to make a phishing message look completely legitimate, as a Greek lawyer discovered after receiving a WhatsApp message linked to a real reservation.

George Linakis described the incident in a Facebook post, saying he narrowly avoided an electronic fraud attempt that appeared to be connected to a hotel he had actually booked through Booking.

The message claimed that he needed to complete a “pre-verification” of his payment card by following a link. If he failed to do so by the following day, he was warned that his reservation would be canceled.

The Reservation Was Real

Linakis had made a hotel reservation through Booking.com, with payment scheduled for a later date.

He then received a WhatsApp message from someone who appeared to represent the hotel. The message directed him to a link where he was supposedly required to confirm his card.

According to Linakis, the website he was taken to closely reproduced the familiar Booking environment, making the process look like an ordinary step connected to his existing reservation.

He also received an OTP, adding another layer of apparent legitimacy.

Detail That Raised the Alarm

Linakis said he could not find where the OTP was supposed to be entered.

That prompted him to stop and reconsider what was happening. He concluded that he was dealing with a phishing attempt and warned others to be particularly careful.

“Luckily, I narrowly escaped it,” he wrote in his warning.

When One Booking Is a Trap

The incident highlights a particularly difficult form of phishing: messages that contain information relating to a genuine transaction.

A traveler may reasonably expect communication from a hotel after making a reservation, particularly when the message appears to contain the correct accommodation details and uses a familiar booking platform’s identity.

Travelers who receive a request to confirm payment details should avoid using the link in the message. Instead, they should check the reservation directly through the official Booking website or app and contact the hotel using independently verified contact details.

Always treat unexpected requests for card information, payment confirmation, or an OTP with caution, even when the underlying reservation is real.

Categories: Greece
Arthur Butler: Arthur Butler is Argophilia’s resident writing assistant and creative collaborator. He helps shape evocative stories about Crete and beyond, blending cultural insight, folklore, and travel detail into narratives that feel both personal and timeless. With a voice that is warm, observant, and a little uncanny, Arthur turns press releases into living chapters and local legends into engaging reads.
Related Post