Tips · July 31, 2026 · 7 min read
Hotel booking scams: how to spot them and stay safe
"Verify your card" messages after booking, copycat sites, ghost listings: the most common schemes and the 30-second checks that protect you.

Travel-related fraud grows every year, and it does not just catch the careless: today's scam messages quote your real name, your real hotel and your real dates, because they arrive after you book, inside channels you consider safe. The good news: almost every scheme collapses under a couple of thirty-second checks. Here are the ones worth knowing before you travel.
The most dangerous scheme: phishing AFTER you book
How it works
You book normally. Days later you receive a message — often inside the platform's own chat, or by email with the exact details of your stay — saying the payment "failed" or your card "must be verified within 24 hours, or the booking will be cancelled". The link leads to a page identical to the real one, where you enter your card details. End of story: the details belong to the scammers. This happens when some properties' systems are compromised — which is why the message knows your real details.
How you defuse it
- No hotel and no serious platform asks you to re-enter your card via a link in chat or email. Ever.
- Urgency is the scam's signature: "within 24 hours", "immediately", "or you lose the room".
- If in doubt, do not use the link: open the site or app yourself, go to your booking and check its status. Or call the hotel on the number from its official site.

Copycat sites and ghost listings
The clone site
You search for a hotel and click the first result: a site that looks like the hotel's (or a well-known platform's) but with a slightly different domain. Great prices, payment only by bank transfer or card on an unprotected page. Always read the domain in the address bar letter by letter, and distrust anyone accepting ONLY bank transfers: a transfer cannot be disputed.
The ghost listing
Beautiful apartments at unreal prices, photos stolen from other listings, and a request to "lock in the deal" by paying outside the platform. There is exactly one rule: payment NEVER leaves the protected circuit. Whoever asks you to pay "outside" — transfer, top-up cards, crypto — is asking you to give up every protection.
The too-good price
A five-star at a third of the market price for the same dates on every other platform is not a bargain: it is bait. Comparing several platforms is itself a security check — if one price is wildly out of line with all the others, the right question is "why?".
The 30-second checks, in order
Before paying
- Is the domain exactly the official one? (Watch for swapped letters and extra hyphens.)
- Is the payment page protected (padlock, https) and run by a recognisable processor?
- Is the price plausible against other platforms for the same dates?
- Are the cancellation terms written clearly before payment?
After booking
- Save the confirmation with its code: that is your title.
- Ignore every "verify your card" link — always, no exceptions.
- If a message rushes you, it is almost certainly fake: genuine communications do not expire in 24 hours.

How you pay matters as much as where you book
- A credit card is the best-protected instrument: in case of fraud you can dispute the charge (chargeback). Prepaid cards cap the maximum damage.
- Transfers to private accounts and crypto offer zero protection: no serious booking requires them as the only method.
- A professional payment processor never has you type your card into an improvised page: look for the signs of banking infrastructure (3-D Secure, your bank's verification step).
On Edenfinder, payment is processed by Nuitee on certified banking infrastructure: your card details never touch our servers, and the total you see is the total you pay.
Your anti-scam checklist
- Read the domain letter by letter before entering any data.
- Compare the price across platforms: an out-of-scale offer is bait.
- Never pay outside the protected circuit, and never by transfer only.
- Ignore every "verify your card" link received after booking.
- In doubt: open the site or app yourself and check the booking from there.
Good to know
I received a message asking to verify my card — what do I do? Do not click the link. Open the app or site where you booked and check the booking's status yourself: if a payment were really needed, you would see it there. If in doubt, call the hotel.
How do I recognise a clone site? By the domain: read it letter by letter in the address bar. Clones use near-identical domains (a swapped letter, a hyphen, a different extension) and often accept only transfers.
I entered my card on a suspicious site — what now? Call your bank and block the card, then watch the statements. If you paid by credit card, request a chargeback for any fraudulent charge.
Are free-cancellation bookings safer? They reduce the financial risk if something feels wrong: you can cancel without penalty before the deadline. The mechanics are in our free-cancellation guide.
How does Edenfinder handle payments? Payment is processed by our travel partner Nuitee on certified banking infrastructure; card details never touch our servers, and you receive the hotel's own confirmation code.
The golden rule is simple: whoever rushes you is scamming you. Take your thirty seconds of checks, then search hotels and book with peace of mind.
Edenfinder
Paradise has a price. We find it lower.
We compare prices for the same hotels across every major booking platform, with direct links to the right page.
Search your hotel →Frequently asked questions
I got a message asking me to verify my card — is it real?
Almost certainly not: no hotel and no serious platform asks you to re-enter your card via a link in chat or email. Open the site or app where you booked and check the booking status there; if in doubt, call the hotel.
What is the safest way to pay for a hotel?
A credit card on a professional payment circuit: in case of fraud you can dispute the charge. Distrust anyone accepting only bank transfers or payments outside the platform — there is no protection there.
How do I recognise a fake booking site?
Read the domain letter by letter: clones use near-identical addresses with a swapped letter or an extra hyphen. A price wildly below every other platform is the other red flag.
From the same section
Destinations

