Sunday, August 09, 2026
Maspalomas 24h | Newspaper of Maspalomas and Southern Gran Canaria
Red alert in Maspalomas due to a very credible hotel scam that steals real booking data

Red alert in Maspalomas due to a very credible hotel scam that steals real booking data

YURENA VEGA - M24H Tuesday, August 04, 2026

 

The tourism sector in southern Gran Canaria is the target of a sophisticated cybercrime campaign. The Internet User Security Office (OSI), part of the National Cybersecurity Institute (INCIBE), has issued an urgent alert after detecting a wave of fraudulent messages circulating on WhatsApp that impersonate hotels and accommodation complexes. The most alarming aspect of this scam, which has already affected travelers with reservations in key tourist destinations like Maspalomas, is that the cybercriminals handle real details of accommodations with absolute precision, achieving a level of credibility that is very difficult to detect at first glance.

The fraudulent messages arrive directly on customers' mobile phones, impersonating the reception or reservations department of the hotel where the user plans to stay. What dispels the victims' suspicions is the inclusion of specific and reliable data, presumably extracted from previous leaks or security breaches: the exact name of the hotel, the precise check-in and check-out dates, the guest's full name, and even the booking reference number.

Under the urgent pretext of needing to validate, confirm, or resolve an administrative issue with the stay, scammers urge the victim to click on a web link. This hyperlink immediately redirects to a fake payment gateway or website that perfectly mimics the visual identity of the accommodation or online booking platform used. Once on the fraudulent page, the customer is asked to enter sensitive personal data and banking credentials under the guise of reconfirming the reservation, at which point the financial fraud and identity theft are completed.
 
Given the proliferation of this impersonation campaign, which could potentially be replicated through phone calls or personalized emails, cybersecurity authorities have established a strict prevention and response protocol to protect travelers visiting the south of the island: Do not click on any links: If you receive a suspicious WhatsApp message about a hotel reservation, you should avoid clicking on any attached URLs or interacting with the sender. Verification through official channels: If you have any doubts about the actual status of a reservation in Maspalomas, you should check it by accessing the hotel's official website directly or contacting them through their usual business phone numbers.

It is advisable to immediately block the sender's number, delete the conversation, and report the incident through the OSI channels. If credit card or bank account details have been entered, it is vital to urgently contact the financial institution to cancel the products and collect screenshots to file a formal complaint with the State Security Forces. For expert advice or to resolve doubts about the legitimacy of a communication, INCIBE reminds users that its free cybersecurity helpline remains operational at 017.

With your registered account

Write your email and we will send you a link to write a new password.