No components marked as affected
Resolved
Informational notice, no Conduit systems were affected. Full details are in the notice above.
Monitoring
Over the past week, guests of hospitality operators around the world, including some Conduit customers, have received WhatsApp messages posing as Airbnb or Booking.com booking confirmations. The messages use the guest's real name, the real property name and the real stay dates, then link to a fake payment page.
We investigated whether Conduit was the source. It was not. Some of the targeted guests had no phone number in Conduit at all. The affected guests booked through Airbnb, Booking.com, Expedia and other channels. Our access logs show no unusual reads, exports or API activity on any affected account. Bitdefender has tracked this same campaign across the industry since March 2026, and it traces back to credential theft at hotels and travel partners.
Tell upcoming guests you never ask for payment over WhatsApp, and that they should only pay through the platform they booked on. If a guest reports one of these messages, forward it to security@conduit.ai.