Skip to main content
ThreatPhishing & impersonation

Fake Booking.com / Hotels.com / Expedia credential phishing — non-OTA sender impersonates travel booking platforms with fake payout-on-hold, payment-declined, unusual-login, or refund-pending alerts designed to harvest host banking details or guest credit card information

fake-booking-hotel-platform-credential-phish

What this tier means

High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.

How Gorganizer detects this

Phishing emails impersonating Booking.com, Hotels.com, or Expedia targeting either hosts or guests. Host-targeting variants: fake payout-on-hold notices claiming the host's banking information cannot be verified and requesting account re-authentication to release earnings — the login page harvests Booking.com Extranet credentials. Guest-targeting variants: fake payment-declined alerts threatening automatic reservation cancellation unless the guest updates their credit card, or fake unusual-login security alerts restricting account access until identity is verified. Key facts: (1) FTC 2024: travel platform impersonation phishing surged 200% — Booking.com is the most impersonated OTA globally, receiving 3x more phishing reports than Expedia and Hotels.com combined; (2) Real Booking.com host payouts are managed entirely within the Extranet — Booking.com will NEVER send an unsolicited email with a "verify banking details" link; (3) Real Hotels.com and Expedia payment failure notices only arrive after a failed charge attempt on a confirmed booking — they always include your booking reference number, which phishing emails typically omit; (4) Legitimate OTA security alerts come from verified domains (@booking.com, @hotels.com, @expedia.com) and never include urgent "account suspended" language without a prior login attempt. Warning signs: non-OTA sender domain, payout/payment urgency without booking reference, request for banking details or card re-entry via email link, "account temporarily restricted" framing.

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started