You book a hotel, the trip is weeks away, and then a text arrives: your reservation is 'pending verification' — just click this link to provide some requested information. It feels routine because we've all been trained by airlines and hotels to expect exactly this kind of security admin. That's precisely what makes it effective as a con.

Travellers are reporting a phishing scheme that targets people with real, upcoming hotel bookings. One Reddit user shared a WhatsApp message received before a stay in Tokyo. The dates matched, the hotel name matched — everything looked right except the link. When someone checked the URL's domain, it turned out to have been registered only a day earlier, with no identifiable owner. The user skipped the link and contacted the hotel through the email on their original confirmation instead. The hotel's answer: it had sent no such message.

More replies followed from other travellers who'd received similar texts tied to genuine reservations at other properties. That's the worrying part. The pattern suggests scammers may be pulling real booking data — names, dates, hotel details — from hotel systems, possibly without the hotels even knowing they've been compromised. Armed with accurate details, the fraud messages look like a legitimate follow-up rather than a random blast from an unknown number.

The US Postal Inspection Service warns about a close cousin of this trick, often called 'smishing': fake package-tracking texts that work because the recipient already expects contact from the sender. The psychology is the same here. A message that arrives in the context of something you actually did — booking a room — lowers your guard in a way a cold-call scam never could.

The defence is simple but requires breaking the reflex to click. Don't tap the link. Don't reply to the message. Set it aside and check with the company directly, using contact details you already have from your booking confirmation or the hotel's official website — never anything supplied in the suspicious text. If the message is genuine, the hotel will confirm it; if not, you've lost nothing but a minute.

It's worth applying this beyond hotels. Any unsolicited text asking you to verify, confirm or update details — whether it claims to be from an airline, a delivery firm or your bank — deserves the same treatment. A real booking never gets cancelled because you refused to click a link; but a clicked link can hand over the details that empty your account. For anyone with an overseas trip on the horizon, the takeaway is to treat confirmation-style messages the way you'd treat a stranger claiming to be a friend: verify through a channel you trust before engaging.