Starting 28 September 2026, Booking.com no longer passes the traveller's phone number into your PMS, your channel manager, or any other connected system. In the 90 days before the change, one arrival in three at the hotels we work with came through Booking.com, and 7 in 10 of those guests were reached on WhatsApp before they arrived. For any hotel running that journey off the PMS number, that conversation has now stopped.
We're working on a solution so your Booking.com guests keep receiving their WhatsApp messages, and you can join the waitlist further down this article. First: what changed, why, what still works, and what to fix now.
What Booking.com changed, exactly
Booking.com no longer transmits guest phone numbers automatically through its connectivity channels. It told partners in an email on 22 September 2026, six days before the change took effect on 28 September. The number still exists. You can see it in the Extranet (Reservations, open the booking, click Show phone number) and in the Pulse app (Bookings tab). What stopped is the automatic hand-off to every system connected to your Booking.com account.
- No PMS or channel manager linked to Booking.com? Nothing changes for you.
- Still coming through: Booking.com's own messaging system, and the masked guest email address ending in @guest.booking.com.
For almost every hotel with a PMS, a Booking.com reservation now arrives with the name, the dates, a masked email and an empty phone field. The change is worldwide and deliberate. Connectivity provider NextPax put it plainly to its own customers: "a deliberate change by Booking.com, not a bug or an outage."
Why Booking.com stopped sharing guest phone numbers
Because the phone number is what the scammers were using.
Booking.com's stated reason is a rise in fraudulent messages sent to guests, usually pressuring them to transfer money urgently to keep their reservation. They arrive by WhatsApp or SMS and, in Booking.com's own words, include real reservation details, which makes them more believable.
The pattern behind these attacks is well documented. Criminals phish the hotel first, with an email that looks like Booking.com raising a guest complaint or an urgent booking problem. They harvest the front desk's Extranet login. Now they can see every upcoming reservation: name, dates, booking reference and phone number. Then they message the guest on WhatsApp with a fake payment page. Microsoft Threat Intelligence described one such campaign in March 2025, and Bridewell mapped the three-stage chain from hotel inbox to guest's card in June 2026.
In April 2026 it became a breach. Booking.com confirmed on 13 April that unauthorised third parties may have accessed reservation data including names, email addresses, phone numbers and booking details. Security researchers pointed to compromised hotel partner accounts as the likely entry point. Guests received WhatsApp scams quoting their real hotel and dates, and at least one reported the scam two weeks before Booking.com's own notification arrived.
Booking.com's answer is to shrink the number of places a phone number lives. Every PMS, channel manager and messaging tool on a hotel account is one more place a stolen login could read it from. Cut the feed, and the number sits behind one login instead of five.
For travellers, a good decision. For hotels, a reminder of whose guest this was.
What still works, and what each channel can't do
Here is where each channel stands since the change, and the limit worth knowing before you rebuild your pre-arrival journey around it.
| Channel | Before 28 September | Since 28 September | Limits worth knowing |
|---|---|---|---|
| Phone number in the PMS | Arrived with the booking | Empty. Manual lookup in Extranet or Pulse, per reservation | Fine for one guest. A job at 400 arrivals a month. |
| WhatsApp / SMS journeys | Triggered from the PMS number | Only for guests whose number you retrieved, or who messaged you first | Every automated flow keyed on the phone field needs checking. |
| Booking.com messaging | Available | Unchanged | Open from booking until seven days after checkout. Images only as attachments, no PDFs. With the AllowList on, links limited to your approved list. |
| Masked email (@guest.booking.com) | Available | Unchanged | Reads as Booking.com correspondence. In our data, fewer than 2 in 100 Booking.com guests were reached this way. |
| Your own web app or webchat | Available | Unchanged | The traveller has to open it, usually from a message they already received. |
The seven-day window is the detail most hotels miss. Booking.com's partner help centre says you can message a guest from the time of booking until seven days after check-out, and that only images are supported as attachments. A "come back in spring" offer a month after checkout, a house guide or a digital key sent as a PDF: none of that can go through Booking.com's inbox. It has to go by email, or through a channel the guest opened with you directly.
What the change costs a hotel, in real arrivals
One Booking.com guest in three was talking to their hotel on WhatsApp before arrival, and that is the conversation the change puts at risk. These are our own platform numbers for the 90 days before the change (27 June to 25 September 2026, cancellations excluded), across the hotels we work with:
- 80,000+ arrivals in total
- 32% came through Booking.com
- 70.5% of those Booking.com guests received a WhatsApp message before arrival, and 1 in 3 Booking.com guests wrote back
- Fewer than 2 in 100 were reached by email, and under 1 in 100 through Booking.com's own messaging
Put that on a single property. A hotel with 200 arrivals a month has, at those averages, 64 Booking.com arrivals. Around 45 of them would have received a WhatsApp two days out, and around 21 would have replied: a question about parking, a breakfast booked, a late arrival flagged. Without a plan, those 45 conversations no longer start.
The cost isn't a security setting. It's the pre-arrival conversation with one guest in three.
Watch out for the placeholder number in your PMS
Some PMSs won't accept a reservation without a phone number, so some connectivity providers now fill the empty field with something else. NextPax has told its customers it adds the relevant Booking.com Customer Service number to each reservation so bookings keep flowing. If your messaging tool sends a pre-arrival WhatsApp to whatever sits in that field, it is now messaging Booking.com's call centre.
Ask your PMS or channel manager what they write into the phone field for Booking.com reservations, and pause any automation that relies on it until you know.
Five things to do now
- Audit every automated message that uses the phone field. Pre-arrival WhatsApp, SMS door codes, checkout reminders. For each one, decide: email, Booking.com messaging, or wait until the number is retrieved.
- Turn on two-factor authentication for the Extranet and the PMS. It is Booking.com's first recommendation, and the one that stops most of the attacks described above.
- Enable the messaging AllowList in the Extranet. Unapproved links can't leave your account, even if someone else is inside it. Booking.com explains the setting in its messaging security guide.
- Brief the front desk. The attack starts with an email that looks like Booking.com about a "guest complaint". Nobody at Booking.com will ever ask for a password.
- Decide who retrieves phone numbers, and when. If WhatsApp matters to your guest journey, someone opens the Extranet each morning for the next day's arrivals.
If you're rebuilding the pre-arrival sequence anyway, our WhatsApp automation playbook covers the templates, the 24-hour window and what Meta now charges for.
We're working on a solution to keep WhatsApp running for your Booking.com guests
Most of our hotels run their pre-arrival conversation on WhatsApp. So the day Booking.com's email arrived, this became the job.
The goal is simple: your Booking.com guests get the same journey they got before 28 September. The WhatsApp two days out, the breakfast and parking offer, the answer at 22:40 in German, the check-in details, the guide. No guest who booked through Booking.com treated differently from one who booked with you.
In the meantime, nothing goes quiet. Booking.com messages land in the AskWhisper inbox next to WhatsApp, email and webchat, and your reply reaches the guest inside Booking.com. Anything Booking.com's inbox can't carry goes to the guest's Booking.com email address and opens in the web app, no download needed. And every guest who gave you their number themselves, on your website or by messaging your WhatsApp first, is untouched.
Why one platform absorbs this and five tools don't
Booking.com gave six days' notice. Think about what that meant for a hotel with a PMS from one vendor, a channel manager from another, a WhatsApp tool from a third, a key provider that texts door codes, and an upsell tool that reads the phone field. Five support tickets. Five roadmaps. Five different answers about what happens to the next arrival.
AskWhisper runs the website, the booking, the pre-arrival, the in-stay and the post-stay from one place, reading from one record.
- Discovery
- Booking
- Pre-arrival
- In-stay
- Post-stay
When Booking.com changes a rule, we change it once, and it holds for every channel and every hotel we run. That is what a platform is for. The next change Booking.com makes, and there will be one, lands on us, not on your front desk. We make the longer case in platform versus point solutions.
The guest who booked with you directly is the guest nobody can switch off
Booking.com changed the terms of your access to your own guest with six days' notice. It could, because it was never your guest. The number was theirs to share. The email is masked. The chat window closes a week after checkout.
None of that is true of a traveller who found your website, liked what they saw, and booked there. That phone number, that email address, that conversation belong to your hotel for as long as the guest wants to hear from you. And that guest is worth more: they book breakfast and parking two days out, they answer the feedback request, and they come back without you paying a commission to be found again.
This is the whole argument for direct bookings, made by Booking.com on your behalf. Website tools stop at the booking. Guest tools only wake up after it. AskWhisper is the only platform that runs the whole journey, and it starts with a website that turns more lookers into bookers, because every direct booking is a guest relationship no platform can edit. The five levers that move that share are in how independent hotels get more direct bookings.
Keep talking to your Booking.com guests
If 7 in 10 of your Booking.com guests were on WhatsApp with you before 28 September, there's no reason to lose them now. Join the waitlist, or book twenty minutes with us and we'll show you the journey running across every channel, and what a website that converts does to your share of direct bookings.
Turn lookers into bookers. Just Ask Whisper.





