The National Cybersecurity Institute (Incibe) issued a Level 4 alert on July 31st, out of five possible levels, to warn about identity theft attempts via WhatsApp in hotel reservations. The aim is to alert the thousands of people planning to travel during the summer and in the coming months.
Although there are no official statistics since 2024, both Incibe and Hosbec confirm that 'phishing', whether via WhatsApp or email, has become a significant problem for users and, especially, for hoteliers. The hotel association indicates that the incidence of complaints or fraud attempts has increased exponentially with the incorporation of automated systems using artificial intelligence in booking procedures.
Mayte García, executive director of Hosbec, highlighted that a diagnosis was made mid-year and communication and cybersecurity training for staff have been reinforced. Although they do not have specific data, they consider it "important that the public be warned and pay attention to possible messages requesting any financial amount or other types of calls".
The head of the hotel association in the Valencian Community explains that the typical case detected arrives via WhatsApp or email, but there have also been cases of hackers cloning hotel websites, making users believe they are booking on an official site.
Daniel Compaño, Business Development Manager at Recursos en la Red (RENR), explains that hotel bookings have become a lucrative business for cybercriminals. He emphasizes that the generated distrust is logical, as these cases were sporadic just over a year ago.
Compaño details that the use of AI has accelerated these fraudulent practices. "The main difference is that the customer will be asked to do something, a key, a payment... that goes beyond the reservation itself," and they will do so by impersonating the booking platform or the hotel itself.
Incibe recommends that if a suspicious WhatsApp message is received, do not click on the link or provide any personal or banking details. Do not continue the conversation with the sender either. The fraud can be reported to Incibe, the sender blocked, and the conversation deleted.
If you have a reservation, it is recommended to check its status using the hotel's official channels. If you have accessed a suspicious link but have not entered any data, close the page. If you have entered banking details, inform your bank immediately.
Database theft is a serious problem, as hoteliers are often responsible for protecting this identity information, and the law imposes hefty fines for such breaches. Compaño emphasizes the importance of staff training, as fake emails also arrive at hotels aiming to access booking data.
The main instructions for users include not opening suspicious messages, not providing personal data, and carefully verifying web addresses, as scammers can copy logos and images, adding just one extra letter to the hotel's name. Doubt and not rushing are key security measures.




