South African hotel bookings hijacked
By Luis Monzon

Criminals are exploiting data leaked from breaches affecting the hospitality industry to run reservation-hijack scams in South Africa.
They are exploiting stolen booking information or compromised hotel accounts to impersonate accommodation providers and solicit travellers’ payment information.
Rory Montgomery, managing director of Hospitality Technology International (HTI), previously told MyBroadband that South Africa’s hospitality industry was under attack by cybercriminals.
In June, HTI was affected by a data breach of its property management cloud system by a Russian threat actor using a novel AI-powered attack technique.
According to the researchers who discovered the breach, the attack exposed 2 million records of private customer information.
The information included full names, email addresses, phone numbers, check-in and check-out dates, and hotel names logged into HTI’s cloud platform, which services companies in South Africa.
The Russian hacker behind the breach used an open-source, generative AI-powered cybersecurity tool to carry out the attack.
“The Russian hacker bypassed LLM guardrails by disguising malicious intent with supposed penetration testing,” researchers said.
“Inside the exposed hacker server, our team discovered that, with the help of AI, attackers crafted at least 50 penetration test reports targeting companies in the accommodation sector.”
Two months earlier, Booking.com notified users in South Africa that their private data may have been exposed when the platform suffered a data breach.
“We’re writing to inform you that unauthorised third parties may have accessed certain booking information associated with your reservation,” the company’s notice said.
“Based on the findings of our investigation to date, accessed information could include booking details, names, emails, addresses, phone numbers, and anything that you may have shared with the property.”
Organisations in the hospitality industry were among those affected by an unprecedented rise in data breaches, with incidents increasing by 60% in the first half of 2025 alone.
Reservation-hijacking scams in South Africa

In a conversation with Cape Talk, cybersecurity educator Boikokobetso Makhetloane detailed how cybercriminals hijack official accounts from hotels and businesses to scam South Africans.
“Reservation-hijack scams are when a scammer takes over a hotel’s account and begins impersonating the hotel,” he said.
“The scammer or attacker would act as the hotel itself, asking customers to confirm certain things. They can lure and trick customers into giving them more money.”
Makhetloane explained that these scams can assume many forms. Usually, they take the form of phishing attacks.
A cybercriminal or scammer has information that a certain person has an active booking at a hotel or company, and then launches communications to this person to solicit financial information.
Makhetloane gave the example of the significant amount of customer data stolen in the Booking.com breach.
“These scammers still have this data and are still impersonating the hotel staff and using company names,” he said.
“We found one of them here in South Africa. A company from Hong Kong, but they are impersonating a company here in South Africa.”
With these genuine booking or company details, scammers use AI to craft communications that appear legitimate and send them to customers, impersonating businesses.
Makhetloane said that an immediate red flag to look out for is the inclusion of urgency in their communication. He noted one scam in which threat actors attempted to get bank card information.
“What these guys have done is say, ‘Hey, you need to pay the remaining amount for your accommodation, so here’s a link to make the payment’.”
“The link will expire in five to 10 minutes. Make sure that you put in your card details.” They will claim that when the link expires, the booking will be cancelled.
The attack aims to cause panic among customers, overriding their natural suspicions about a potential scam, or to study the communications for flaws or other red flags.
“It’s not about you making the payment, it is about you inputting your card details to authorise the payment to go through. They are looking for and harvesting your card details,” Makhetloane said.
He urged South Africans to double-check any communications they receive from hotels or hospitality companies, especially if they have recent bookings.
The best way to get information is to call the official numbers listed on these companies’ websites, rather than relying on email or SMS.