In our digital age, basic travel planning can swiftly descend into a carnival of member logins, confirmation emails, two-factor authentication calls, CAPTCHA requests, 24-hour advance check-ins, and other security busywork.
So if vacationers receive a text with a confirmation link from a hotel they've recently booked, it's just one more thing to take care of, right?
Not so fast.
Consumers are reporting a simple-looking text-based scam that appears to be a sophisticated phishing scheme designed to collect personal information about you.
The scam goes like this: You make a reservation with a hotel. Time goes by. Shortly before your stay, you receive a text that informs you that your booking is "pending verification" and asks you to click a link to provide "requested information."
That's what happened to Reddit user Pastelchannl, according to a recent post about a WhatsApp message received before a hotel stay in Tokyo. The dates and the name of the hotel included in the message looked correct—but the link the Redditor was asked to click looked strange.
Upon closer investigation by someone who knew how to check, it turned out the domain name of the URL had only been created a day earlier. There was no way to determine who owned the domain.
Wisely, Pastelchannl did not click the link.
Instead, they did exactly the right thing: contacted the hotel using its official communication channels and asked if the text was authentic.
It was not. The hotel said it hadn't sent anything. The text was a scam.
After the original Reddit post, other users chimed in right away to report that a similar thing had happened to them, too, based on their own hotel reservations elsewhere.
It would appear, based on such accounts, that scammers are hacking information about valid upcoming reservations from hotels—and the hotels might not even be aware a breach has happened.
Fraudsters then use authentic reservations to send messages to future guests as a Trojan horse that appears, on the surface, to be legit.
Guests who aren't paying close attention and click the provided link make themselves subject to phishing operations that can expose more personal and financial details.
The scam is similar to "smishing," the bogus package-tracking texts that the United States Postal Inspection Service warns consumers about. People are seduced into letting down their guards and clicking invasive links when a text message appears to be from a business they're already familiar with.
The only way to verify if an unexpected confirmation request is truly from a hotel or travel vendor is to contact that vendor directly, without using any of the contact information included in the text.
The Reddit user above contacted the hotel through the email address that appeared on the original reservation confirmation receipt to find out that the text was a fraud.
If you receive one of these notifications, whether it's by text or a messaging app like WhatsApp, do not click any links and don't reply. Instead, set the message aside and verify its authenticity through other channels.