A few days ago I received a Whatsapp message from our New York City hotel requesting payment. Knowing I had a few weeks to cancel/confirm my booking, I thought the 11 hour deadline was rather weird. It turns out, it was a Booking.com scam. A VERY convincing scam that absolutely nearly caught me (and would have put me out of around $1300).
When I Googled the service, nothing came up. So I’m determined to get this online as soon as possible and share my experience with the intention of saving others from these revolting criminals. Here’s how I nearly fell for a booking.com scam via Whatsapp. *Note: I will use the fake website within quotation marks such as “booking.com”.
Booking.com Scams
Over R45 margaritas with a friend last week, she happened to mention that there had been a few Booking.com scams of late. She suggested I contact all my hotels directly to ensure my bookings were reserved. Agreeing, we went on with our Friday night knowing I’d get to this before departure date.
How I Nearly Got Booking.com Scammed
Having spent a considerable amount of time (read days) planning and booking our North American trip, you can imagine I thought receiving a Whatsapp message from our New York City Hotel as fairly important.
The Whatsapp message said I had an 11 hour deadline, however, at that precise moment I was dealing with our pizza order that was incorrect and on the way shortly. Yet, concerned about the booking, I immediately clicked the link and jumped to the “booking.com” page on my mobile that insisted I made payment – even if I had made payment.
Immediately my spidey senses went off, however, I said to myself – I have 11 minutes to fix the pizza order or 11 hours to fix the hotel order. Let me focus on the pizza first. THANK GOODNESS I took this breather!

Why It Was So Convincing
- Firstly, it was a direct Whatsapp message, meaning they had my mobile number. It arrived on my phone, while I was at home – and considering GDPR and the POPIA act, people shouldn’t have my number unless we’ve had a legal touch point.
- Secondly, the website link mimicked the Booking.com branding EXCEPTIONALLY well. It absolutely looked like it was related.
- Thirdly, they had the exact hotel name where I was staying. So it wasn’t a foreign hotel, it was a real life booking I had made with the correct dates.
- Fourth, my name and mobile number were preloaded into the website form exactly.
How was that done? Does that happen because they scrape my Whatsapp data and it automatically loads? Or perhaps they scraped the pixel or cookie data? Or did they scrape the Booking.com website? I don’t believe America has as strict data laws so selling personal data is common in the country. Perhaps they simply bought my data? Who knows. But it was accurate.
What Does the Booking.com Scam Look Like?
- There are 2 parts – the Whatsapp message and the website they actually direct you to. When I saw the URL, it looked similar to a hotel booking service like Nightsbridge, which is common on independant websites – but not used on the official booking.com website. The language was convincing though, “homes veri” almost like verified – but not.

- I also noticed that the country icon within “booking.com” had the Union Jack, meaning it was in Pounds, but I live in South Africa and have seen the South African flag depicted to confirm our currency (South African Rand).

- The third thing was the 11 hour deadline – that was in conflict with the Booking.com offers, which is one of the major factors of why we love the site! They’ll hold your booking if you’d prefer to pay later.

- Fourth, it said I was getting the best price – which did not match the price I had agreed to on the official site. Having spent hours, nay DAYS, trawling New York City hotel websites, Google maps and Booking.com trying to find hotels with the best value – it seemed very odd that I was magically getting $300 off the price I had already committed to. I haven’t added a picture here as I don’t want to reclick on the scam link.
How Did I Verify it was a Booking.com Scam?
- One of the first steps was to cut and paste the URL into my browser and see if a website loads at all. Immediately it was flagged as a “Dangerous Site”.

2. Then I noticed the reservation number at the end of the URL, that being “60999982”. I immediately logged onto booking.com and checked my reference number – they did not match.

3. My next step was to Google the telephone number that had been used to Whatsapp’d me. I was hoping someone else had flagged it or shared other warnings. Absolutely nothing came up – which is also a red flag as it’s nearly impossible for absolutely nothing to come up on Google.

4. Then I Googled the country code (+62) as I was pretty sure the USA is +1 – and THIS as a first big clue. +62 is for Indonesia. I’ve never been to Indonesia or Australia or Asia, not used any business in that area so to receive any message from an Indonesian number was highly unlikely.

5. Finally, I reached out to Booking.com and found they had left an automatic warning on their first DM. I had missed this at the time, but they reconfirmed that they will never use Whatapp to reach out to a client.

What the Whatsapp Message Said?
Reservation information
Hello Meg Sproat,
This message concerns your reservation 60999982 at [Hotel name[, scheduled for 2026 [start date] β 2026 [end date]. Your booking is currently in a pending state and requires confirmation to remain active.
Status: Pending confirmation
Deadline: 11 hours 13 minutes
To continue, please review your reservation details and complete the confirmation process via the link below [Fraudulent Link]:
Once completed, the reservation will be automatically updated in the system. Before proceeding, please verify:
β’β β All reservation details are accurate
β’β β The confirmation is completed within the available timeframe
β’β β The process is finished without interruption
If no action is taken within the specified time, the reservation may be released. For assistance, our support team is available.
Kind regards,
[The Hotel in Question]
Reservations Support Team
How To Avoid a Booking.com Scam
- Trust your instincts. If you feel ANY resistance, do your research.
- No matter how convincing the website is, DO NOT PUT YOUR BANKING DETAILS IN.
- Google any details you can – the number, the website…any decent company will have a business website.
- Reach out to the hotel, check if they really need your details and then proceed (clue, they probably don’t).
- BLOCK BLOCK BLOCK
- Do not engage and tell these people they are *&%^&*, because it may give them more access to you. Less is more.
Rely on your instincts and official sources and leave it at that. How do you know if it’s an official source? You call them. You get the number from their official website and you make a telephone call. Or you mail them. Just because you receive a mail doesn’t mean you’re obliged to answer it. It’s safer for you to reach out; that way you know who YOU are calling/mailing and aren’t just receiving calls/mails on face value.
I really hope this helps and assists you in avoiding any dodgy engagements with these global criminals.
Happy travelling!