A message appears to come from Booking.com. It says a reservation is at risk, a payout has failed, or the property must verify its account immediately. The link looks plausible, the timing is stressful, and the person on duty wants to protect the booking. One click can turn an ordinary shift into an account-security incident.
For Greek hosts, villas, apartment managers, and small accommodation businesses, this risk is operational—not theoretical. Booking.com’s own safety guidance describes partner account takeover, phishing, fraudulent bookings, and compromised third-party systems as threats to accommodation partners. The platform also warns that its representatives will not ask for an account password or sensitive financial details.
The answer is not to distrust every guest or ignore every urgent message. It is to create a verification process that remains safe when the front desk is busy, the manager is off-site, or a seasonal employee is covering several properties. This guide explains the warning signs, the first-response workflow, and the controls Greek operators should put in place before the next suspicious message arrives.
Why a convincing Booking.com message can be dangerous
Phishing works by creating a believable reason to act before thinking. In short-term rentals, the attacker can exploit familiar pressure points: a high-value reservation, a last-minute cancellation, an alleged payment problem, a guest who cannot access the property, or a warning that the listing may be suspended.
Booking.com’s official safety guidance for partners says account takeover is frequently the result of phishing and may lead to fraudulent transactions or unauthorised access to guest details. It also describes fraudulent bookings that can block availability, cause late cancellations, or support manipulation that leads to account takeover.
A message does not become trustworthy merely because it contains a reservation number, the property name, or a guest’s dates. Some information may already be public, may have been exposed through another compromised system, or may come from an account the criminal has accessed. Treat context as a reason to investigate—not as proof of identity.
The most important rule: verify through a separate route
If a message asks you to sign in, confirm payment details, install software, open an attachment, or act urgently, do not use the link or contact method inside that message. Open Booking.com or the Extranet independently using your normal bookmark or a manually entered address. Check whether the alert, reservation change, or support case also appears inside the authenticated account.
This is called out-of-band verification: you confirm the request through a channel that the suspicious message did not control. If the issue is supposedly from Booking.com, contact Partner Support from within the Extranet. If it concerns a bank transfer or card, use the number or app you already use for the bank—not a number supplied by the sender.
Booking.com states that its partner service representatives will only ask for the property ID and will not ask for the account password or sensitive financial information such as a credit-card number. A caller or message that requests those details has crossed a clear safety boundary.
Seven warning signs Greek hosts should recognise
1. Artificial urgency
“Verify within 30 minutes,” “your listing will be deleted,” or “the guest will lose the reservation” are designed to interrupt normal checks. A real operational problem may be time-sensitive, but urgency never removes the need to verify it through the Extranet.
2. A login link inside a message
The visible text may say Booking.com while the destination is a different domain, a shortened address, or a carefully misspelled copy. Do not test the link. Navigate independently to the platform and look for the same request.
3. Requests for passwords, codes, or full payment details
Never send a password, two-factor authentication code, card number, or online-banking credential in chat, email, or over the phone. A one-time code is effectively a temporary key; sharing it can defeat the protection it was meant to provide.
4. Instructions to install software or share the screen
A supposed support agent may offer to “fix” the account by asking an employee to install a remote-access tool or share the desktop. This can expose browser sessions, guest records, channel-manager data, and banking access. End the interaction and verify the case from the official support area.
5. A payment destination that suddenly changes
Bank details, refund routes, or payment instructions should never be changed solely because of an inbound message. Compare the request with the account’s authenticated payment information and apply a second-person approval for any financial change.
6. Pressure to move the conversation away from the platform
A request to continue on WhatsApp, Telegram, personal email, or a new phone number can remove the conversation from the record your team and the platform can review. Booking.com advises partners to keep guest communication within its messaging system and to avoid sharing personal contact information before meeting the guest.
7. A story that does not match the reservation
Check the dates, guest name, amount, cancellation conditions, property, and message history in the Extranet or channel manager. A real reservation with one altered detail can be more persuasive than a completely invented booking. Record the inconsistency and escalate it rather than improvising.
The first 15 minutes after a suspicious message
A written response plan is faster than panic. Use this sequence:
- Stop the interaction. Do not click, download, reply, call the supplied number, or forward the message to a personal account.
- Verify independently. Open the Extranet from the usual bookmark and inspect the reservation, payment area, notifications, and support inbox.
- Preserve useful evidence. Keep the original message and record the time, sender, channel, visible address, and actions already taken. Do not circulate guest or payment data more widely than necessary.
- Alert the responsible manager. Use an internal contact method already known to the team. If several properties share access, assume the potential impact may extend beyond one listing until checked.
- Contact official support. Report suspicious activity through Booking.com’s authenticated support route. Explain whether anyone clicked, entered credentials, approved a code, installed software, or changed payment details.
If nobody interacted with the message, the event may end with reporting, blocking, and a team reminder. If someone entered credentials or approved a code, treat it as a possible compromise rather than merely an attempted scam.
If someone clicked or entered information
Use a clean, trusted device to access the official account. Change the affected credentials and ensure two-factor authentication is enabled. Booking.com recommends 2FA because it adds a verification step when a username and password are compromised.
Then review the parts of the operation that an attacker would value: account users, property information, guest messages, payout instructions, recent reservation changes, and connected tools. The exact controls available vary by account, property type, payment setup, and software connections, so use Partner Support to confirm what should be reviewed or reset.
If banking or card information was entered, contact the financial institution immediately using an independently verified channel. Do not wait for an unauthorised transaction to appear. If remote-access software was installed, disconnect the affected device from operational use and obtain qualified technical help before signing back into business systems.
Operators should also consider whether guest data may have been accessed. This can create legal and contractual obligations beyond restoring the platform login. Seek appropriate cybersecurity and data-protection advice for the facts of the incident rather than assuming a password change closes the matter.
When and where to report an incident in Greece
Report the issue to Booking.com through the authenticated partner channel so the platform can review the account or reservation. For suspected computer fraud or illegal access in Greece, the official gov.gr computer-fraud complaint service allows a signed complaint to the Hellenic Police Cyber Crime Division and lets the complainant attach relevant evidence.
In an active financial incident, contact the bank or payment provider immediately as well. Platform support, law enforcement, the bank, and a cybersecurity professional perform different roles; contacting one does not automatically protect every part of the business.
Build a safer operating system before peak season
The best defence is a workflow that does not rely on one employee spotting a perfect fake. For a Greek property manager with apartments in Athens, villas on an island, or remote seasonal staff, the following controls reduce rushed decisions:
- enable two-factor authentication and never share authentication codes;
- limit account access to people who currently need it and review access when staff or contractors change;
- use unique credentials and a reputable password manager where appropriate;
- require independent verification for payout, bank, refund, and account-detail changes;
- keep a printed or offline incident contact list for Booking.com support, the bank, the channel manager, and the responsible manager;
- train cleaners, co-hosts, reception staff, and outsourced teams never to install software or share screens on an unsolicited request;
- run a short phishing drill before the busiest booking period; and
- document which device and person may approve sensitive changes.
These controls also support other channels. Our broader guide to short-term-rental payment scams in Greece covers suspicious guest payments and refund requests, while the article on Booking.com virtual credit cards addresses the separate cash-flow workflow. Operators building their own sales channel should also review trust and security signals for direct-booking websites.
A five-question decision test for every urgent message
- Can I see the same request after opening the official platform independently?
- Is anyone asking for a password, authentication code, full card details, software installation, or screen sharing?
- Does the request change where money is sent or how a refund is processed?
- Do the guest, dates, amount, property, and policy match the authenticated reservation?
- Has a second authorised person verified the action through a known channel?
If any answer is unsafe or uncertain, pause and escalate. A legitimate guest may wait a few extra minutes while the team verifies a request. Recovering from account takeover, diverted payouts, or exposed guest information can take far longer.
The bottom line
The most dangerous Booking.com phishing message is not necessarily the one with bad spelling. It is the one that arrives at the right time, uses familiar reservation details, and convinces a busy team member that normal verification is too slow.
Greek hosts should make independent verification, two-factor authentication, limited access, and dual approval for financial changes part of everyday operations. Treat urgent links as unverified, use the Extranet and established contact routes, and record what happened when something looks wrong.
This article provides general operational information, not legal, cybersecurity, banking, or data-protection advice. Platform tools and procedures can vary by property, account, payment model, contract, and date. Confirm current requirements inside your own Booking.com Extranet and obtain professional advice for an actual incident.

