Travel Industry Cybersecurity: AI-Powered Threats & Booking.com’s Defense

by priyanka.patel tech editor

The travel industry, a prime target for cybercriminals, is facing increasingly sophisticated attacks, particularly as travel rebounds post-pandemic. Booking.com, one of the world’s largest online travel agencies, is bolstering its defenses against a surge in fraud, leveraging artificial intelligence and enhanced partner monitoring to protect both customers and its network of lodging providers. The company’s Chief Information Security Officer, Marnie Wilking, emphasized the growing need for collaboration across the hospitality sector to stay ahead of evolving threats.

While the manufacturing industry currently bears the brunt of cyberattacks, according to IBM’s 2026 X-Force Threat Intelligence Index report, the hospitality sector has seen a marked increase in malicious attention in recent years. “It’s definitely become more targeted over the last several years, especially post-Covid, when travel really picked back up again, and has really gone crazy since then,” Wilking said. “So, there’s clearly quite a bit of money to be made there.” This rise in targeted attacks underscores the importance of robust cybersecurity measures for companies like Booking.com and the broader travel ecosystem.

The Evolving Threat Landscape

A key driver of this increased threat is the rapid advancement of artificial intelligence. Threat actors are now using generative AI to create highly convincing phishing emails and fake property listings, making it harder for users to distinguish legitimate offers from scams. “Again, it gets easier, in particular with generative AI, because it’s so easy to generate beautiful-looking images, really well-written and great grammar emails in any language,” Wilking explained. Beyond phishing, Booking.com and the wider retail and hospitality industry are experiencing a rise in account takeovers and credential stuffing attacks – a tactic that exploits the common practice of reusing passwords across multiple platforms.

The company has also seen instances of brand abuse, where malicious actors leverage the Booking.com name in malware campaigns. In January, security researchers at Securonix uncovered a campaign using the Booking.com brand in a fake blue screen of death malware attack, as reported by IT Brew. This highlights the need for constant vigilance and proactive measures to protect both the company’s reputation and its users.

Booking.com’s Multi-Layered Defense

Booking.com’s security strategy centers on a layered approach, combining preventative measures with robust detection and response capabilities. On the user side, the company has implemented one-time passwords to mitigate the risk of credential stuffing attacks. Yet, prevention is only part of the equation. Booking.com also prioritizes understanding its partners – the property owners and managers who list their accommodations on the platform – and monitoring their behavior for suspicious activity.

“Do we know where they normally log in from? Do we know when they normally log in?” Wilking asked. “Gathering all of that information and being able to put some risk-based authentication in place right away to say, ‘Do we really reckon that this person is who we think they are?’” This risk-based authentication system adds an extra layer of security by flagging unusual login attempts for further scrutiny.

The company is also heavily investing in AI-powered detection tools. These tools analyze messages and login attempts to identify potentially malicious activity. “The ability to use AI to detect malicious messages, to detect potentially malicious logins, has really put us in a better place, and we have a high level of confidence when somebody logs in that it is who we think it is, and that they’re doing the things that we expect them to do,” Wilking said.

These efforts have yielded tangible results. In 2023, Booking.com blocked approximately 1.5 million phishing-related fake reservations. Following the implementation of latest controls, that number decreased to around 250,000 fake reservations in 2024.

Collaboration and Education: A Shared Responsibility

Recognizing that cybersecurity is a shared responsibility, Booking.com actively collaborates with industry partners and provides educational resources to both customers and lodging providers. The company works closely with the Retail and Hospitality ISAC (Information Sharing and Analysis Center), an organization that facilitates the exchange of threat intelligence among industry members. Booking.com also maintains an online Trust and Safety Resource Center, providing best practices and updates on emerging threats.

“We give [partners] as much information as we can and update [our Trust and Safety section] as frequently as we can when there are new attacks, new scams coming out,” Wilking said. User education is also a priority, with Booking.com adding banners to its website explaining common scams, particularly during peak travel seasons.

Looking Ahead

As cyber threats continue to evolve, Booking.com remains committed to investing in cutting-edge security technologies and fostering collaboration across the travel industry. The company will continue to refine its AI-powered detection systems and enhance its partner monitoring capabilities. Booking.com is also focused on staying ahead of emerging threats, such as those leveraging increasingly sophisticated AI tools. The next step involves continued refinement of its risk-based authentication protocols and expansion of its educational resources for both customers and partners.

What are your thoughts on the evolving cybersecurity landscape in the travel industry? Share your experiences and concerns in the comments below.

You may also like

Leave a Comment