Short-term rental payment scams in Greece do not always begin with an obviously fake guest. They often begin with a normal-looking inquiry, a plausible story and a request that shifts payment, communication or identity checks away from the channel where the reservation started. For Greek villa owners, apartment hosts and small accommodation operators, one rushed decision can create a chargeback, a fake payment confirmation, an account takeover or a stay with no recoverable funds.
The goal is not to distrust every guest. It is to build a payment workflow in which genuine travellers move quickly while unusual requests receive additional verification. This guide covers Airbnb, Booking.com and direct reservations, explains the most common warning signs, and provides a practical response checklist.
Start with the platform where the booking originated
Airbnb’s official Off-Platform and Fee Transparency Policy prohibits moving current, future or repeat bookings away from Airbnb and generally prohibits reservation payments outside the platform, subject to limited disclosed exceptions. It also restricts requests for contact information before booking. Hosts should use Airbnb’s approved tools for reservation changes and eligible payment requests.
This is more than a commission issue. A conversation that leaves the platform may remove evidence needed during a dispute and expose both parties to phishing. Never follow a link sent by a supposed guest to “confirm” an Airbnb payout, reactivate a listing or release funds.
Booking.com reservations can use different payment arrangements depending on the property, guest and account. Review the reservation inside the Extranet or your connected property-management system, not in an email alone. Booking.com’s official connectivity documentation shows that reservation data can include payment details, policies, guest information and whether a virtual credit card is involved. The exact workflow and commercial terms vary by account.
Red flag 1: the guest wants to overpay
A classic scammer offers to send more than the reservation total, then asks the host to refund the difference to a driver, agent, relative or supplier. The original payment later fails or is reversed, while the host’s “refund” was a real transfer.
Never accept an unexplained overpayment. Refund only through the original, verified payment channel and only after confirming the transaction in the platform or payment processor dashboard. A screenshot, PDF receipt or email confirmation is not proof that funds settled.
Red flag 2: pressure to leave the platform
Messages such as “WhatsApp me because the app is broken” or “send your bank details to secure the booking” create urgency and reduce traceability. For an Airbnb-originated inquiry, follow Airbnb’s policy and keep communication and payment on the platform. For Booking.com, use the Extranet messaging and the payment method assigned to that reservation.
A direct-booking inquiry is different because no OTA transaction exists. Even then, direct guests should receive a secure booking page, written terms, a clear cancellation policy and a processor-generated receipt—not informal bank instructions in a social-media chat.
Red flag 3: a payment link sent by the guest
Hosts normally send an approved payment request; guests do not need to send a link so the host can “claim” money. A fake page may copy Airbnb, Booking.com, Stripe, Viva, PayPal or a Greek bank and ask for card details or online-banking credentials.
Open the service through your saved bookmark or type the official address yourself. Do not sign in through a link inside a guest message. Check the actual reservation from the dashboard and contact official support through the platform if the status is unclear.
Red flag 4: a booking confirmation visible only in email
Logos and reservation templates are easy to imitate. If an email announces a new booking but the reservation does not appear in the Extranet, Airbnb dashboard, PMS or channel manager, treat it as unverified. Do not block dates, share access instructions or arrange a refund until the booking exists in the authoritative system.
Red flag 5: unusual refund instructions
A guest may ask for a refund to a different card, bank account or person. This breaks the payment trail and can create double loss if the original payer later disputes the charge. Refund to the original method using the platform or processor workflow. If that is impossible, pause and obtain written guidance from the responsible payment provider.
Red flag 6: a virtual credit card that is not yet chargeable
Booking.com virtual credit cards have activation dates, expiry dates and charge conditions. Attempting to charge at the wrong time can fail without indicating fraud. Conversely, treating an email as proof of a valid card can be risky. Check the reservation and card conditions in the Extranet. Our detailed guide to Booking.com virtual credit cards in Greece explains the cash-flow controls operators should use.
Red flag 7: high-value stays with weak identity consistency
A different guest name, cardholder, email and arrival contact does not automatically prove fraud; families and corporate travel can involve multiple people. It does justify a consistent verification step. Use only information permitted by the platform and Greek law, avoid collecting unnecessary identity data, and document why any additional check is required.
Never ask for sensitive documents through an insecure channel simply because a booking feels unusual. Data protection and fraud prevention must work together.
Red flag 8: last-minute urgency plus expensive extras
A same-day reservation followed by requests for airport transfers, shopping, equipment or third-party payments can increase exposure. Separate legitimate hospitality from financial forwarding. Do not buy gift cards, pay a courier, transfer money to a driver chosen by the guest or purchase refundable goods on the promise of later reimbursement.
Red flag 9: requests to install software or share a screen
No guest or legitimate platform agent needs remote access to the host’s computer to confirm a reservation. Do not install an app, browser extension or “security certificate” sent in a message. Never share one-time passwords, backup codes or authentication prompts. Platform support can verify cases through official channels without controlling your device.
Red flag 10: mismatched totals across systems
A PMS, channel manager and OTA can display different fields: gross price, commission, taxes, platform-collected amounts and expected payout. A mismatch may be configuration rather than fraud, but it must be reconciled before issuing money. Compare the reservation ID, dates, guest, currency, payment model and final payout line by line.
Reliable synchronization also prevents fake “double booking” emergencies. Review the limits of iCal versus a channel manager in Greece if multiple channels sell the same unit.
Red flag 11: a chargeback threat used as leverage
An unhappy guest may threaten a chargeback unless the host provides an instant off-platform refund or additional service. Keep the conversation factual. Preserve photos, timestamps, messages, access logs, invoices and the accepted policy. Use the platform or processor dispute process instead of making an undocumented transfer under pressure.
A safer workflow for direct bookings
Direct reservations can reduce channel dependence, but the host becomes responsible for controls that an OTA may otherwise provide. At minimum, use:
- A secure booking engine with HTTPS and a reputable payment processor.
- Written rates, taxes, fees, cancellation terms and house rules before payment.
- Processor authentication and fraud tools appropriate to the transaction.
- A reservation number linked to the payment and guest record.
- Access controls so staff see only the data required for their role.
- A documented refund process returning funds to the original method.
- Regular backups and multi-factor authentication for business accounts.
Do not market direct booking by soliciting an existing platform guest in violation of channel rules. Build independent demand through your own website, email list collected lawfully, repeat-guest strategy, local partnerships and useful destination content.
The five-minute verification checklist
- Open the reservation in the original platform or booking engine.
- Match the reservation ID, dates, guest and amount.
- Confirm who is responsible for collecting payment.
- Check whether funds are authorized, captured, pending or payable later.
- Review cancellation and refund conditions.
- Keep communication in the approved channel.
- Refuse third-party transfers and unexplained overpayments.
- Use official support opened from the platform itself.
- Record the decision and evidence.
- Escalate high-value or inconsistent cases to the manager or processor.
How professional operators reduce risk
Fraud controls should not depend on one person’s intuition. Create a standard operating procedure for reservations, payment status, refunds, identity exceptions and after-hours escalation. Train cleaners and check-in staff not to accept payment changes at the door. Limit administrator access and remove accounts when team members leave.
Review conversion and payment problems separately. If a listing receives traffic but not bookings, avoid accepting risky requests merely to fill the calendar. Diagnose the commercial issue using our guide to Booking.com views without bookings. Discounts and visibility tools, including Booking.com Genius in Greece, should be evaluated on net revenue, not used to override payment controls.
Final advice for Greek hosts
The safest rule is simple: verify the reservation where it originated, verify money in the responsible payment system, and never let urgency replace procedure. Most guests are genuine, and a clear process improves their experience because staff can answer confidently and quickly.
Payment terms, platform features, processor rules and legal obligations can vary by account and operating status. Review the current contract and obtain professional accounting or legal advice where needed. A strong Greek short-term-rental business protects revenue not only by winning bookings, but by ensuring every booking, payment and refund follows a traceable path.

