Beware of scams impersonating travel platforms, $185,000 lost since January: Police谨防冒充旅游平台的诈骗,自1月以来已损失18.5万美元:警方
Booking.com scam warning: Police say phishing messages have led to at least 148 cases and $185,000 in losses since January. Read more at straitstimes.com.
Published Oct 09, 2026, 06:40 PM
Updated Oct 09, 2026, 06:40 PM
Police warned that scammers are sending WhatsApp and email phishing messages using real booking details. At least 148 cases have been reported since January.
Victims are tricked into clicking links and entering card details. This has caused at least "$185,000" in losses, and one man’s warning post drew over a million views.
Booking.com said it never asks for card details by text, WhatsApp, email or phone. Police urged people to use ScamShield, two-factor authentication and official checks.
SINGAPORE – Travellers are being targeted by convincing phishing messages that contain details of their actual accommodation bookings, including their travel dates and destinations, with at least 148 cases reported since January.
The police said in a statement that victims would receive messages, mostly through WhatsApp, or emails from scammers impersonating hotels or hotel booking platforms, prompting them to verify their card details or confirm their upcoming accommodation bookings.
In some instances, the messages or emails contained legitimate booking details, lending credibility to the scam, the police added.
Victims would then be instructed to access a phishing link to secure their bookings by providing their bank card information on the webpage and authorising the resulting transactions.
The police said that victims would only realise they had been scammed after unauthorised transactions were made to their bank cards, and upon checking in with the hotel directly.
To date, the total losses from these scams have amounted to at least $185,000.
Similar to the methods mentioned in the police advisory, a Singaporean man said in an Instagram post on Sept 12 that he received a WhatsApp message about his upcoming Booking.com reservation requiring “one final action”.
The Singaporean man, who booked his trip through Booking.com, was informed that the payment system has not received any final confirmation.
He was directed to a website, which displayed details of his actual reservations, including the date and location of his accommodation. At the bottom of the page, the man was prompted to enter his payment details.
While he did not enter his payment information as instructed, he subsequently warned others about the scam. His post has since garnered over a million views.
In a response to media queries, Booking.com said it is aware of phishing attempts that were carried out through WhatsApp.
“Booking.com will never ask customers to provide credit card details via text, WhatsApp, email or phone call. We will also never ask them to make a bank transfer that differs from the payment policy stated in their booking confirmations,” the travel platform’s spokesperson said in its response on Sept 18.
The spokesperson reminds customers that they should avoid clicking on unfamiliar links or sharing sensitive information, and verify payment requests through the Booking.com app, with the hotel directly or the 24/7 customer service team.
“Anyone who has already shared information or made payment should contact their bank immediately and our customer service team,” the spokesperson said.
Booking.com had suffered a data leak in April , during which unauthorised parties may have accessed information associated with some customer reservations.
Information potentially accessed included customers’ names, booking details, e-mail addresses and phone numbers.
The platform did not provide further details on the scale of the breach, such as the number of customers affected. The spokesperson also confirmed that customers’ financial information and physical addresses were not accessed through Booking.com’s system.
It subsequently said that updated PINs were provided for reservations affected by the unauthorised access, and customers were informed accordingly.
The police advised members of the public to adopt several precautionary measures to avoid falling for scams.
These included downloading the ScamShield app, setting up security features such as two-factor authentication and money lock features for banks and e-wallets, checking for signs of scams with official sources, and informing authorities, family and friends about scams.
For more information on scams, members of the public may also call the 24-hour ScamShield Helpline at 1799, or visit www.scamshield.gov.sg .
发布于2026年10月9日下午6:40
更新于2026年10月9日下午6:40
警方警告称,诈骗分子正利用真实的预订信息,通过 WhatsApp 和电子邮件发送钓鱼信息。自 1 月以来,已报告至少 148 起此类案件。
受害者被诱骗点击链接并输入银行卡信息。这已造成至少18.5万美元的损失,其中一名男子发布的警告帖子浏览量超过百万。
Booking.com表示,他们绝不会通过短信、WhatsApp、电子邮件或电话索取银行卡信息。警方敦促民众使用ScamShield、双重验证和官方查询功能。
新加坡——一些不法分子利用具有欺骗性的钓鱼信息,诱骗旅客获取其真实的住宿预订信息,包括旅行日期和目的地。自今年1月以来,至少有148起此类案件被报道。
警方在一份声明中表示,受害者会收到诈骗者冒充酒店或酒店预订平台发送的信息(大多通过 WhatsApp)或电子邮件,诱使受害者验证其银行卡信息或确认即将到来的住宿预订。
警方补充说,在某些情况下,这些信息或电子邮件包含合法的预订详情,这增加了诈骗的可信度。
受害者随后会被指示访问钓鱼链接,通过在网页上提供银行卡信息并授权由此产生的交易来确保预订成功。
警方表示,受害者只有在银行卡被盗刷后,以及在酒店办理入住手续时,才会意识到自己被骗了。
迄今为止,这些骗局造成的总损失至少已达 185,000 美元。
与警方公告中提到的方法类似,一名新加坡男子在 9 月 12 日的 Instagram 帖子中表示,他收到了一条关于他即将到来的 Booking.com 预订的 WhatsApp 消息,要求他进行“最后一个操作”。
这位新加坡男子通过 Booking.com 预订了行程,但被告知支付系统尚未收到最终确认信息。
他被引导到一个网站,网站上显示了他实际预订的详细信息,包括住宿日期和地点。页面底部提示他输入付款信息。
虽然他没有按照指示输入付款信息,但他随后警告其他人提防这种骗局。他的帖子目前已获得超过一百万的浏览量。
Booking.com在回应媒体询问时表示,他们已经注意到有人通过WhatsApp进行网络钓鱼攻击。
Booking.com发言人在9月18日的回应中表示:“Booking.com绝不会通过短信、WhatsApp、电子邮件或电话要求客户提供信用卡信息。我们也绝不会要求他们进行与预订确认函中所述付款政策不同的银行转账。”
发言人提醒顾客,应避免点击不熟悉的链接或分享敏感信息,并通过 Booking.com 应用程序、直接与酒店或 24/7 全天候客户服务团队核实付款请求。
发言人表示:“任何已经分享信息或付款的人都应该立即联系他们的银行和我们的客户服务团队。”
Booking.com 在 4 月份遭遇了一次数据泄露事件,期间未经授权的第三方可能访问了与某些客户预订相关的信息。
可能获取的信息包括客户姓名、预订详情、电子邮件地址和电话号码。
该平台并未提供有关此次数据泄露规模的更多细节,例如受影响的客户数量。发言人还确认,客户的财务信息和实际地址并未通过Booking.com的系统被访问。
随后该公司表示,已为受未经授权访问影响的预订提供了更新后的 PIN 码,并已相应地通知了客户。
警方建议公众采取若干预防措施,以避免落入诈骗陷阱。
这些措施包括下载 ScamShield 应用程序,为银行和电子钱包设置双重身份验证和资金锁定等安全功能,通过官方渠道检查诈骗迹象,以及将诈骗情况告知当局、家人和朋友。
如需了解更多有关诈骗的信息,公众还可以拨打 24 小时 ScamShield 热线 1799,或访问 www.scamshield.gov.sg。