Phishing 2026: the scam that already knows your booking details
A WhatsApp message with your first name, your hotel's logo and your check-in date. Everything looks legitimate. That is exactly where the danger lies. A look at the new faces of phishing in 2026 and what you can do about it.
Back in 2023, we wrote about a phishing attempt targeting one of our clients. You know, those dodgy emails impersonating your bank or a postal service to get money out of you. Since then, scammers have seriously done their homework and it has never been more urgent to stay sharp.
Booking data leaked three days later
A little while ago, I booked and paid for a hotel in France directly on their website. The transaction went through, I received the confirmation email straight away, everything looked perfectly normal. Three days later, late in the evening, I got a WhatsApp message from an unknown number based in the United States. I paused for a second because the hotel logo, the name of the establishment, my check-in date, my first name… it was all there. The message explained that my booking was not finalised and that I needed to click on a link and simply leave the page open.
My first instinct was to block and report the number and take screenshots to contact the hotel and flag a potential data leak.
The response came in two stages. First, I received a quick reply, very casual in tone: “Yes, there is a scam impersonating the hotel, we are aware of it.” and, as if to reassure me, “please note that the information these individuals have access to is your stay dates, first name and last name, no banking details whatsoever.”
No further explanation. No apology. No indication of what had been compromised or what I should do next.
Knowing my subject and being particularly mindful of data protection, I pushed for more details : how extensive was the breach, when did it happen? …
The second response was… something else: “[…], certain booking data (name, email address, phone number and stay dates) may have been accessed in a limited manner by unauthorised third parties, without it being possible to confirm with certainty whether your file was specifically affected.”
Having received a fraudulent WhatsApp message three days after my booking, it is fairly safe to conclude that yes, my file was affected.
What should have happened after this data breach
In one of their responses, the hotel mentioned that these scams aim to rob victims of their money. The financial aspect is obviously a serious concern. But all the other personal data is just as sensitive : your name, your gender, your phone number, your country of residence… All of this is equally valuable and potentially just as devastating in the hands of unscrupulous individuals.
Beyond that, the hotel’s breezy response is not just disappointing on a human level. It is potentially illegal.
In Europe, the General Data Protection Regulation (GDPR) sets very clear obligations for companies in the event of a personal data breach.
The company’s obligations:
A company that suffers a data breach has 72 hours to notify the relevant data protection authority. In Belgium, that is the Data Protection Authority (APD). In France, it is the CNIL. If the breach presents a high risk to the rights and freedoms of the individuals concerned, the company must also directly notify the affected people, clearly and within a reasonable timeframe. That notification must specify the nature of the breach, the data compromised, the likely consequences and the measures taken or planned.
A dismissive message stating that there has been a data breach but that you are not affected does not constitute a compliant notification, especially when you have just received a fraudulent message containing your own data.
Your rights as a victim:
If you believe a company has failed to meet its obligations following a data breach affecting you, you have the right to file a complaint with the relevant authority. In Belgium, head to the APD website. Since my hotel was in France, I could have filed a complaint with the CNIL. You can also request, in writing, access to information about the breach and the measures taken to address it. This request falls under your right of access as guaranteed by the GDPR.
2026: scams on every channel
This kind of experience perfectly illustrates how phishing has evolved in 2026. The techniques have changed, grown more sophisticated and become far harder to spot. Here are a few that deserve your full attention.
WhatsApp and SMS phishing
Suspicious emails ending up in spam are so last decade. Scammers have moved to more immediate and more personal channels. A text or a WhatsApp message creates a far stronger sense of urgency than an email, and our guard is naturally lower when we receive them.
The technique is well-rehearsed: a data breach at a trusted provider as a hotel, an online shop, an airline, hands scammers your name, phone number and the context of your purchase. All they need to do is build a tailored message using the official logo and the right details. The only giveaway is often tiny: a slightly off WhatsApp account name or a URL that looks right but isn’t quite.
If you receive this kind of message after a purchase, always contact the establishment directly through their official website before clicking on anything.
Quishing: malicious QR codes
Since QR codes went mainstream during Covid, a new form of scam has quietly taken hold: quishing. The concept is straightforward. A fraudulent QR code replaces or covers a legitimate one in a restaurant, on a poster, in an email or even in an official document. You scan it without a second thought and get redirected to a site that perfectly mimics a payment page, a login screen or an identity verification form.
The tricky part with QR codes is that the destination URL is not visible before you scan. A few habits are worth building: check that the QR code is not a sticker placed over another one, look at the URL displayed after scanning before doing anything on the page and be wary of any QR code received by email or message that creates a sense of urgency.
Vishing and voice deepfakes
This is probably the most unsettling form of phishing in 2026. Thanks to artificial intelligence, it is now possible to clone a voice from just a few seconds of audio recording, recordings that are easy to find on social media, YouTube videos or podcasts.
The most common scenario in a professional context: you receive a call from what sounds exactly like your CFO or your manager, asking you to make an urgent and confidential transfer. The voice is right. The intonation is right. The urgency feels real.
In a personal context, it might be the voice of a loved one claiming to be in trouble and needing money fast.
The fix: agree on a code word or an alternative verification channel with your colleagues and close ones for any urgent financial request, regardless of whose voice is on the line.
Fake AI tools and websites
The enthusiasm around artificial intelligence tools has created fertile ground for scammers. Dozens of fake websites impersonating ChatGPT, Claude, Gemini or other popular tools are created every week, with the goal of stealing your login credentials, your payment details or installing malware on your device.
The basic reflex: always access these tools through their official URL saved in your bookmarks and never through a link received by email or a sponsored result in a search engine. Sponsored results can point to fraudulent sites that have paid to appear at the top of the page.
AI in the hands of scammers: the end of spelling mistakes
For a long time, spelling mistakes and clunky grammar were the most reliable red flags for spotting a fraudulent message. That is no longer the case. AI tools can now generate perfectly written messages in any language, with the right level of formality and even mimicking the communication style of a specific brand.
That does not mean you should panic, but it does mean you can no longer rely on writing quality alone to judge whether a message is legitimate. The other warning signs described in this article and in our 2023 post are more relevant than ever.
The 2026 checklist
Here are the essential reflexes to adopt when facing new forms of scams:
Before you click
- Is the sender really who they claim to be? Check the number, the email address or the account name not just the logo displayed.
- Does the message create artificial urgency? This is one of the most widely used techniques to bypass your better judgement.
- Did you receive this message through an unusual channel for this type of communication? A bank will never contact you via WhatsApp.
- Does the displayed link actually match the destination URL? Hover over it without clicking to check.
- Is it a QR code received by email or message? Be cautious and check the URL before taking any action.
Before you enter your details
- Are you on the organisation’s official website? Check the full URL in your address bar.
- Is the site using HTTPS? A padlock in the address bar is the bare minimum but not a guarantee on its own.
- Is a voice asking you to make an urgent transfer? Hang up and call back using the official number or your agreed code word.
After an online purchase or booking
- Did you receive an unexpected message containing your personal details? Contact the provider directly through their official website.
- Has a company informed you of a data breach in vague or insufficient terms? You have the right to request further details and to file a complaint with the APD or the CNIL.
You clicked?
The same core reflexes apply, but speed is everything.
Do not enter any further information and close the page immediately. If you have already shared banking details, call your bank without delay. Report the fraud attempt to the organisation involved, it helps them warn other customers.
For any compromised account, change your password immediately from a different device if possible and enable two-factor authentication if you haven’t already. If personal data has been stolen, you can also file a complaint with the APD (Belgium).
Finally, report the scam to SafeOnWeb at suspicious@safeonweb.be. Every report helps feed their database and protect other people.
Cover photo by Brett Jordan on Unsplash