The most valuable data stolen from a travel company may not be a credit card number. A genuine booking, hotel name, stay date, vehicle registration or trusted business contact can be enough to make the next scam believable
Recent incidents involving Manchester Airports Group (MAG), Booking.com and BCD Travel show how ordinary customer and business data can become raw material for targeted phishing, impersonation and extortion.
They also expose a structural weakness in travel: a single journey can involve airlines, hotels, airports, online travel agencies (OTAs), travel management companies, payment providers and specialist technology suppliers, all exchanging information.
“The honest answer would be these attacks are rarely exotic,” cybersecurity expert Boštjan Koželj told PhocusWire.
“The picture most people have of hacking—that someone is defeating encryption with a hat in a dark room—that's almost never what actually happens. What happens is that somebody obtains a password or convinces a person to hand [over] personal data.”
Attackers may impersonate an OTA, send a false guest complaint or claim that a payment failed. A link can lead an employee or traveler to a fake login page. Stolen credentials can then open the way to guest data, operational systems or fraudulent messages sent through a legitimate account.
“From there, the outcomes [can be] theft of guest data, ransomware that locks the property management system, payment card skimming on a booking page or abuse of hotels' OTA extranet to defraud the hotel's own guests,” Koželj said. “Nothing mysterious about it.”
How travel data makes phishing convincing
MAG, which operates Manchester, London Stansted and East Midlands airports, disclosed in August that an unauthorized third party had obtained customer information linked to car parking, lounges, Fast Track airport security bookings and airport Wi-Fi registrations. The information included email addresses, phone numbers, vehicle registrations and postcodes.
MAG said the affected system did not hold bank or payment information. But information does not need to contain financial details to be useful to criminals.
“You can conjure up really specific phishing emails,” said Dray Agha, senior manager of tactical response at cybersecurity company Huntress.
He gave the example of a message containing the correct vehicle registration and claiming that the recipient had received a parking ticket.
“I can guarantee more than half will click that link and pay it.”
The Booking.com reservation hijacking incident reflects the same problem. The company confirmed in April that unauthorized parties had accessed information including names, email addresses, phone numbers and booking details.
Researchers at Gen
Digital later documented reservation-hijack scams affecting more than 350
accommodation properties in over 50 countries. Criminals used genuine
reservation information to send messages that appeared to come from hotels.
Riskified’s analysis
of hundreds of millions of travel transactions points to a broader shift.
Fraudsters increasingly use legitimate identities, devices and compromised
travel-platform accounts, allowing them to imitate normal customers and
communications more convincingly.
Stolen information can also remain useful after the original
incident. As The
Beat reported, after BCD Travel disclosed suspicious activity in May, bogus
extortion emails later appeared claiming to be based on the “BCD Travel
database.” The emails did not prove their senders had accessed BCD’s systems,
but they showed how publicity around a real or alleged breach can lend
credibility to later scams.
Agha said attackers often do not know which information will
prove useful until they enter a system. Details that appear mundane can become
“really powerful artifacts” for identity fraud and targeted phishing.
Attackers look for travel's weakest links
Attackers do not always need to penetrate an airline, airport, hotel or booking platform's best-protected systems. They can enter through a supplier.
“Most of the attacks, in my opinion, come from the third party,” Koželj said. “Hotels don't run just one system. They run a dozen companies' systems stitched together.”
“Nobody attacks the fortress anymore,” he added. Instead of going after the largest suppliers, they'll target suppliers with the weakest security.
Koželj pointed to the 2025 Qantas data breach, which occurred through a third-party platform used by a Qantas airline contact center contractor.

Nobody attacks the fortress anymore.
Boštjan Koželj
Agha compared the problem to defending a castle while someone poisons the river upstream.
“We've actually had quite a few cases where it wasn't obvious how a cybercriminal broke in,” he said. “When you investigate it back to the root cause, it was a trusted third party who themselves had been compromised.”
Krasimir Simonski, a cybersecurity specialist who has held senior roles in the Bulgarian government, said companies inevitably have less control over products and systems supplied by others.
“Supply chain is really critical because you don't have much control over it,” he said. If a supplier fails, the risk is “transferred downstream” to customers and users.
A single booking may pass through a global distribution system, property management system, OTA, payment gateway and other vendors. Airlines, hotels and intermediaries also depend on business-to-business APIs, including New Distribution Capability connections and hotel channel managers.
The greater danger is uncontrolled trust: Companies may not know which partners can reach sensitive systems, how long their access lasts or how quickly it can be revoked.
AI makes familiar scams faster
Artificial intelligence (AI) changes the speed and economics of fraud, though not its basic purpose. Agha called AI a “force multiplier for both sides.” Criminals can produce more persuasive messages at scale, while defenders can use the same technology to detect unusual behavior.
Koželj said generative AI can produce “massive, fast and grammatically flawless phishing messages” in languages that once created a barrier for criminals. Those messages can be combined with genuine booking information, while increasingly realistic voice cloning creates another route for impersonation.

AI is making their deception faster. It's making them operate at a speed which is quite difficult really to repudiate if you also aren't using AI.
Dray Agha, Huntress
Agha cautioned against treating AI as an entirely new threat.
“They're just rattling doors,” he said of many opportunistic attackers. “AI is making their deception faster. It's making them operate at a speed which is quite difficult really to repudiate if you also aren't using AI.”
Simonski argues that agentic AI could accelerate attacks further. An AI agent can receive an objective, choose tools, plan steps and adjust its actions without a human issuing every command. In an interconnected travel environment, such systems could identify weak access controls and move between systems faster than human attackers.
That does not make basic controls obsolete. It makes weak credentials, excessive permissions and poorly monitored supplier connections easier to find and exploit.
The best defense begins with basic controls
All three experts agree that the strongest defenses include multifactor authentication, limited privileges, prompt patching, staff training, continuous monitoring and a rehearsed incident-response plan.
Simonski estimated that 90% to 95% of the incidents he encounters can be traced to failures in basic cyber hygiene, including weak password practices and excessive trust.
“The way to defend yourself against AI attacks really isn't to go and buy expensive security tools,” Agha said. “What we see that wins again and again is good cyber hygiene.”
Koželj recommends maintaining an inventory of every supplier and system touching customer information, routing third-party access through company-controlled authentication with at least two factors, restricting permissions and monitoring unusually large data exports.
Simonski advocates zero-trust controls, under which users, devices and suppliers must continue proving they should have access. Measures can include continuous API authentication, short-lived access tokens and network micro-segmentation.
Travel companies can also actively look for vulnerabilities before attackers find them. Agoda, for example, announced a public bug bounty program through HackerOne in June, inviting researchers to test defined parts of its website, mobile app and APIs.
“We’re inviting the global research community in because we believe open, collaborative relationships are how the best security work gets done, especially as companies across all industries work harder to combat the rise in criminal cyberattacks,” Agoda's chief information security officer Yaron Slutzky said.
A bug bounty cannot eliminate social engineering or supply-chain risk, however. Travel companies must protect a chain of people, accounts, suppliers and platforms, not just their central systems.
Agha suggested companies ask one basic question: “If a supplier of ours was compromised today, how would we know, and what could we do about it?”