I made a villa reservation through Booking.com on Friday and 2 days later, at 05:29, I got a WhatsApp message from a WhatsApp Business account displaying the name "Awign. Full transcript, with my name and booking reference redacted:
> Hi [my real first name],
>
> Here is a summary of your reservation:
>
> Property: Lamai Sunshine Villas
> Check-in: 2027-01-06
> Check-out: 2027-01-13
> Booking reference: 674[redacted]
>
> Action required — please verify your reservation using the link below. No payment is taken; any temporary hold is released immediately.
>
> [link to booking.confirm-5937.com, path ending in my real booking reference — address is in the title, not linked here]
>
> We kindly ask you to confirm within 24 hours so your room stays reserved, as it may otherwise be released.
>
> Kind regards,
> Lamai Sunshine Villas Reservations Team
>
> No payment will be charged for this verification.
Below the text was a "Confirm reservation" button. Every detail in that message is correct – property, both dates, and my actual booking reference. The linked page is a visual 1:1 copy of Booking.com with all of my reservation data already filled in. The only empty fields are card number, expiry and CVV, which is the entire point of the exercise.
The giveaways: the domain is confirm-5937.com, with "booking" bolted on as a subdomain so the URL reads convincingly at a glance; the contact came through WhatsApp from an unrelated business account rather than the Booking.com message inbox; there's a 24-hour deadline; and the message insists twice that no payment will be taken, which is exactly what someone collecting card numbers would say.
I didn't enter anything. I blocked and reported the WhatsApp account, reported the message and the domain to Booking.com, and contacted the property on the number listed on Booking.com to confirm the reservation is intact.
Why I'm posting: partly so the domain is on record here, and partly because I want to understand how they had my full reservation record rather than just a name. My understanding is that this normally comes from a property's Booking.com partner extranet account being phished rather than from Booking.com itself – has anyone had a case where the property or Booking.com actually confirmed the source? And is there anything worth doing beyond what I've already done, with the stay still over a year out?
scammer whatsapp message
Source: r/travel · by /u/Prior_Juice_8658
