Booking.com no longer sends guest phone numbers to your PMS. Here's what changed and how to keep talking to your guests.

The phone field on every Booking.com reservation is now empty. What changed, why Booking.com did it, what still works, and what to fix before your next arrival.

Martijn van Dooren9 min read
Share

Starting 28 September 2026, Booking.com no longer passes the traveller's phone number into your PMS, your channel manager, or any other connected system. In the 90 days before the change, one arrival in three at the hotels we work with came through Booking.com, and 7 in 10 of those guests were reached on WhatsApp before they arrived. For any hotel running that journey off the PMS number, that conversation has now stopped.

We're working on a solution so your Booking.com guests keep receiving their WhatsApp messages, and you can join the waitlist further down this article. First: what changed, why, what still works, and what to fix now.

What Booking.com changed, exactly

Booking.com no longer transmits guest phone numbers automatically through its connectivity channels. It told partners in an email on 22 September 2026, six days before the change took effect on 28 September. The number still exists. You can see it in the Extranet (Reservations, open the booking, click Show phone number) and in the Pulse app (Bookings tab). What stopped is the automatic hand-off to every system connected to your Booking.com account.

  • No PMS or channel manager linked to Booking.com? Nothing changes for you.
  • Still coming through: Booking.com's own messaging system, and the masked guest email address ending in @guest.booking.com.

For almost every hotel with a PMS, a Booking.com reservation now arrives with the name, the dates, a masked email and an empty phone field. The change is worldwide and deliberate. Connectivity provider NextPax put it plainly to its own customers: "a deliberate change by Booking.com, not a bug or an outage."

Why Booking.com stopped sharing guest phone numbers

Because the phone number is what the scammers were using.

Booking.com's stated reason is a rise in fraudulent messages sent to guests, usually pressuring them to transfer money urgently to keep their reservation. They arrive by WhatsApp or SMS and, in Booking.com's own words, include real reservation details, which makes them more believable.

The pattern behind these attacks is well documented. Criminals phish the hotel first, with an email that looks like Booking.com raising a guest complaint or an urgent booking problem. They harvest the front desk's Extranet login. Now they can see every upcoming reservation: name, dates, booking reference and phone number. Then they message the guest on WhatsApp with a fake payment page. Microsoft Threat Intelligence described one such campaign in March 2025, and Bridewell mapped the three-stage chain from hotel inbox to guest's card in June 2026.

In April 2026 it became a breach. Booking.com confirmed on 13 April that unauthorised third parties may have accessed reservation data including names, email addresses, phone numbers and booking details. Security researchers pointed to compromised hotel partner accounts as the likely entry point. Guests received WhatsApp scams quoting their real hotel and dates, and at least one reported the scam two weeks before Booking.com's own notification arrived.

Booking.com's answer is to shrink the number of places a phone number lives. Every PMS, channel manager and messaging tool on a hotel account is one more place a stolen login could read it from. Cut the feed, and the number sits behind one login instead of five.

For travellers, a good decision. For hotels, a reminder of whose guest this was.

What still works, and what each channel can't do

Here is where each channel stands since the change, and the limit worth knowing before you rebuild your pre-arrival journey around it.

ChannelBefore 28 SeptemberSince 28 SeptemberLimits worth knowing
Phone number in the PMSArrived with the bookingEmpty. Manual lookup in Extranet or Pulse, per reservationFine for one guest. A job at 400 arrivals a month.
WhatsApp / SMS journeysTriggered from the PMS numberOnly for guests whose number you retrieved, or who messaged you firstEvery automated flow keyed on the phone field needs checking.
Booking.com messagingAvailableUnchangedOpen from booking until seven days after checkout. Images only as attachments, no PDFs. With the AllowList on, links limited to your approved list.
Masked email (@guest.booking.com)AvailableUnchangedReads as Booking.com correspondence. In our data, fewer than 2 in 100 Booking.com guests were reached this way.
Your own web app or webchatAvailableUnchangedThe traveller has to open it, usually from a message they already received.

The seven-day window is the detail most hotels miss. Booking.com's partner help centre says you can message a guest from the time of booking until seven days after check-out, and that only images are supported as attachments. A "come back in spring" offer a month after checkout, a house guide or a digital key sent as a PDF: none of that can go through Booking.com's inbox. It has to go by email, or through a channel the guest opened with you directly.

What the change costs a hotel, in real arrivals

One Booking.com guest in three was talking to their hotel on WhatsApp before arrival, and that is the conversation the change puts at risk. These are our own platform numbers for the 90 days before the change (27 June to 25 September 2026, cancellations excluded), across the hotels we work with:

  • 80,000+ arrivals in total
  • 32% came through Booking.com
  • 70.5% of those Booking.com guests received a WhatsApp message before arrival, and 1 in 3 Booking.com guests wrote back
  • Fewer than 2 in 100 were reached by email, and under 1 in 100 through Booking.com's own messaging

Put that on a single property. A hotel with 200 arrivals a month has, at those averages, 64 Booking.com arrivals. Around 45 of them would have received a WhatsApp two days out, and around 21 would have replied: a question about parking, a breakfast booked, a late arrival flagged. Without a plan, those 45 conversations no longer start.

A printed arrivals list and a phone showing guest messages on a hotel reception desk, the kind of manual check Booking.com guest phone numbers now need.

The cost isn't a security setting. It's the pre-arrival conversation with one guest in three.

Watch out for the placeholder number in your PMS

Some PMSs won't accept a reservation without a phone number, so some connectivity providers now fill the empty field with something else. NextPax has told its customers it adds the relevant Booking.com Customer Service number to each reservation so bookings keep flowing. If your messaging tool sends a pre-arrival WhatsApp to whatever sits in that field, it is now messaging Booking.com's call centre.

Ask your PMS or channel manager what they write into the phone field for Booking.com reservations, and pause any automation that relies on it until you know.

Five things to do now

  1. Audit every automated message that uses the phone field. Pre-arrival WhatsApp, SMS door codes, checkout reminders. For each one, decide: email, Booking.com messaging, or wait until the number is retrieved.
  2. Turn on two-factor authentication for the Extranet and the PMS. It is Booking.com's first recommendation, and the one that stops most of the attacks described above.
  3. Enable the messaging AllowList in the Extranet. Unapproved links can't leave your account, even if someone else is inside it. Booking.com explains the setting in its messaging security guide.
  4. Brief the front desk. The attack starts with an email that looks like Booking.com about a "guest complaint". Nobody at Booking.com will ever ask for a password.
  5. Decide who retrieves phone numbers, and when. If WhatsApp matters to your guest journey, someone opens the Extranet each morning for the next day's arrivals.

If you're rebuilding the pre-arrival sequence anyway, our WhatsApp automation playbook covers the templates, the 24-hour window and what Meta now charges for.

We're working on a solution to keep WhatsApp running for your Booking.com guests

Most of our hotels run their pre-arrival conversation on WhatsApp. So the day Booking.com's email arrived, this became the job.

The goal is simple: your Booking.com guests get the same journey they got before 28 September. The WhatsApp two days out, the breakfast and parking offer, the answer at 22:40 in German, the check-in details, the guide. No guest who booked through Booking.com treated differently from one who booked with you.

In the meantime, nothing goes quiet. Booking.com messages land in the AskWhisper inbox next to WhatsApp, email and webchat, and your reply reaches the guest inside Booking.com. Anything Booking.com's inbox can't carry goes to the guest's Booking.com email address and opens in the web app, no download needed. And every guest who gave you their number themselves, on your website or by messaging your WhatsApp first, is untouched.

Why one platform absorbs this and five tools don't

Booking.com gave six days' notice. Think about what that meant for a hotel with a PMS from one vendor, a channel manager from another, a WhatsApp tool from a third, a key provider that texts door codes, and an upsell tool that reads the phone field. Five support tickets. Five roadmaps. Five different answers about what happens to the next arrival.

AskWhisper runs the website, the booking, the pre-arrival, the in-stay and the post-stay from one place, reading from one record.

The traveller journey, from discovery through to post-stay
  1. Discovery
  2. Booking
  3. Pre-arrival
  4. In-stay
  5. Post-stay

When Booking.com changes a rule, we change it once, and it holds for every channel and every hotel we run. That is what a platform is for. The next change Booking.com makes, and there will be one, lands on us, not on your front desk. We make the longer case in platform versus point solutions.

The guest who booked with you directly is the guest nobody can switch off

Booking.com changed the terms of your access to your own guest with six days' notice. It could, because it was never your guest. The number was theirs to share. The email is masked. The chat window closes a week after checkout.

None of that is true of a traveller who found your website, liked what they saw, and booked there. That phone number, that email address, that conversation belong to your hotel for as long as the guest wants to hear from you. And that guest is worth more: they book breakfast and parking two days out, they answer the feedback request, and they come back without you paying a commission to be found again.

This is the whole argument for direct bookings, made by Booking.com on your behalf. Website tools stop at the booking. Guest tools only wake up after it. AskWhisper is the only platform that runs the whole journey, and it starts with a website that turns more lookers into bookers, because every direct booking is a guest relationship no platform can edit. The five levers that move that share are in how independent hotels get more direct bookings.

A traveller on a sofa browsing a hotel website on a laptop, about to book direct rather than through Booking.com.

Keep talking to your Booking.com guests

If 7 in 10 of your Booking.com guests were on WhatsApp with you before 28 September, there's no reason to lose them now. Join the waitlist, or book twenty minutes with us and we'll show you the journey running across every channel, and what a website that converts does to your share of direct bookings.

Turn lookers into bookers. Just Ask Whisper.

Quick answers

Has Booking.com removed guest phone numbers completely?

No. Since 28 September 2026, Booking.com no longer sends the traveller's phone number automatically to connected systems such as a PMS or channel manager. The number still exists and is visible per reservation in the Booking.com Extranet, under Reservations, and in the Pulse app, under the Bookings tab. Only the automatic hand-off to connected software stopped.

Does this affect my hotel if I don't use a PMS or channel manager?

No. Booking.com told partners that properties without a connected PMS or channel manager see no change, because they already work from the Extranet, where the phone number is still shown. Booking.com's security advice still applies to every property: two-factor authentication on the Extranet, the messaging AllowList, and training staff to spot fake Booking.com emails.

Can I still send WhatsApp messages to Booking.com guests?

Yes, as long as you have the guest's number. You can look it up per reservation in the Booking.com Extranet or the Pulse app, or the guest can message your WhatsApp first. Automated WhatsApp journeys that read the number from your PMS will stop for Booking.com reservations. AskWhisper is building a solution to keep them running.

Is Booking.com messaging a replacement for WhatsApp?

Only partly. Booking.com's messaging works from the moment of booking until seven days after checkout or cancellation. It accepts images as attachments but not PDFs, and with the AllowList switched on it removes any link you haven't approved. Post-stay offers, PDFs and anything later than a week after departure need email or your own channel.

Why did Booking.com stop sharing guest phone numbers?

To cut the number of places a guest's phone number can be stolen from. Criminals have been phishing hotel staff for Booking.com Extranet logins, then using real reservation details to send guests fake payment requests on WhatsApp and SMS. Booking.com also confirmed in April 2026 that unauthorised third parties may have accessed reservation data, including phone numbers.

What should my hotel do first now Booking.com phone numbers are gone?

Turn on two-factor authentication for the Booking.com Extranet and your PMS, then enable the messaging AllowList so unapproved links can't leave your account. Next, list every automated message that relies on the guest's phone number, such as pre-arrival WhatsApp or SMS door codes, and decide how each one reaches Booking.com guests now.
Share

Want this running at your hotel?
Just Ask Whisper.

Describe your property and watch the website build itself. Everything that follows - the messages, the upsells, the reviews - runs from the same place.