Anyone travelling to Spain this summer who has already booked a hotel should be particularly cautious when receiving messages via WhatsApp. The Guardia Civil is warning of a scam in which criminals pose as hotel staff and deceive victims using remarkably accurate information about genuine bookings.
Spain Expat Press Editorial Team
by Marlon Gallego Bosbach
For many holidaymakers, their trip to Spain begins weeks before departure with a hotel booking. It is precisely these reservations that scammers are now exploiting. According to the Spanish Guardia Civil, travellers are being contacted via WhatsApp by criminals posing as staff from their booked hotel. Particularly worrying is that these messages can contain genuine booking details, including the guest’s name, the hotel, travel dates and even the booking reference number.
This makes the message appear completely legitimate at first glance. The scammers often claim that there is a problem with the payment or that the reservation needs to be confirmed again. They then send a link through which the guest is supposedly asked to confirm their booking or update their payment details.
However, the link does not lead to the hotel or the official booking platform, but to a fake website. There, the criminals attempt to steal personal information, credit card details or other sensitive login credentials.
The sinister part: The booking is actually genuine
The new scam differs from many conventional phishing attempts mainly in its level of detail. A message simply claiming that someone has booked a hotel in Spain is relatively easy to recognise as fraudulent. It becomes far more convincing when the message names the correct hotel, the exact arrival date and the traveller’s personal booking reference.
The scammers use precisely this information to gain their victims’ trust. When someone receives a message containing their actual travel details, they may quickly assume that only the hotel could have access to such information. However, accurate booking details are no guarantee that the sender is genuine.
In documented cases, travellers are asked to reconfirm an allegedly failed payment or enter their credit card details via a link they have been sent. Time pressure also plays a key role: victims are sometimes told that their reservation will be cancelled unless they act quickly.
Concrete cases have already been reported
Documented cases in Spain show that the warning is not without reason. Spain’s cybersecurity agency INCIBE reported a case in which a customer received similar messages relating to a genuine hotel booking and later discovered fraudulent charges on their card. The hotel subsequently explained that its account on the booking platform had been compromised and used to contact guests.
Spain’s consumer protection organisation OCU has also received complaints from travellers who lost hundreds of euros after receiving such messages containing genuine booking information.
The threat is not limited to any single booking platform. What matters is that scammers gain access to information about a genuine reservation and then use it to carry out a targeted phishing attack.
Do not verify a WhatsApp message via the link
Anyone who receives such a message should not click on the link under any circumstances. Instead, they should check their booking directly through the official app or website of the relevant booking platform. If there is no indication of a payment issue there, the conversation should be ended.
Calling the hotel directly can also help clarify the situation. However, it is important to use a telephone number from an official source rather than the number provided in the suspicious WhatsApp message.
Holidaymakers should be particularly cautious if they are asked to enter their credit card or bank details again. Even a message featuring the hotel’s official logo, a correct booking reference or professional language is not proof that it genuinely came from the hotel.
What to do if you have already clicked on the link?
Anyone who has simply opened the link but has not entered any information or made a payment should close the page and not proceed any further. However, if credit card details, passwords or other sensitive information have been entered, they should contact their bank or card provider immediately.
If money has already been transferred, the bank should also be contacted immediately and the incident documented. Screenshots of the WhatsApp message, the telephone number, the link used and any payment receipts may later serve as important evidence. In the event of an actual scam, it is also advisable to report the incident to the relevant authorities.
A genuine booking does not mean the message is genuine
The latest warning shows just how sophisticated scams have become. While phishing messages were once often recognisable by poor language, fake logos or obvious spelling mistakes, criminals are increasingly using genuine information and targeted manipulation.
For holidaymakers travelling to Spain, the rule is simple: never deal with unexpected payment or booking confirmation requests via the link provided in a message. If in doubt, open the official booking platform yourself or contact the hotel directly.
That is precisely what makes this scam so dangerous: the message can contain all the correct information about the trip and still come from the wrong people.
Anyone travelling to Spain in the coming weeks should therefore not only keep their booking confirmation to hand, but also remain particularly vigilant when receiving any unexpected messages relating to their hotel.
