
Louisville diners and summer travelers are being urged to watch their wallets as a new AI-driven twist on an old reservation scam hits the region. Fraudsters are using real booking details - names, dates and phone numbers - to pose as hotels and restaurants, then con guests into handing over money or card information. Some people are only finding out they were duped when they walk up to the front desk and are told there is no reservation under their name.
Local experts sound the alarm
Eva Velasquez, CEO of the Identity Theft Resource Center, told WDRB that criminals are mixing breached booking data with AI tools to craft what she called "letter perfect" phishing texts and calls that sound like real staffers. Whitney Adkins of the Better Business Bureau in Louisville told the station that many victims only realize anything is wrong when they arrive, find no booking in the system and discover their money is already gone.
Researchers say the problem is widespread
Norton’s Summer Scam Forecast labels "reservation hijacking" as one of the top threats of the season, according to Norton/Gen Digital. The company warns that scammers lean on real hotel names, true check-in dates and even confirmation numbers to push travelers onto fake payment pages. Norton says reservation hijacking is linked to data breaches and mentions lookalike sites and AI-enabled techniques that can make scams more convincing. Some vulnerability summaries note issues in hotel-booking WordPress themes (the specific 'LoftOcean--CozyStay' reference (CVE-2024-13410) was not found in the cited CISA weekly summaries), underscoring security risks in some booking platforms. Some reports have documented vulnerabilities in systems like the Pinpoint Booking System and discussed phishing and credential-harvesting risks; the specific CISA summary for June 3, 2024 cited here does not contain those references. According to Verizon's 2026 Data Breach Report, 'vulnerability exploitation is now the most common way attackers break in, beating credential theft and phishing as the top initial access method,' a shift that security researchers say can help explain rising compromises of booking platforms and related scams. According to Experian, 'credential exposure, via spear-phishing' can enable broader attacks in the highly connected payments ecosystem, which aligns with industry warnings about booking-data abuse and credential harvesting.
Restaurants and platforms are hardening defenses
Reservation platforms are urging restaurants to clamp down on staff access before scammers can get to guest information. OpenTable stresses that it will never ask restaurants for login credentials, and it recommends two-factor authentication along with quickly reporting suspicious messages to [email protected]. The goal is to keep criminals from exporting guest lists and then recycling those diner details in bogus verification calls and texts.
How to protect yourself
If you get an unexpected booking message, experts say to skip the link or callback number in the text or email and instead contact the hotel or restaurant directly using the phone number on your original confirmation or on the business’s official website. The Identity Theft Resource Center expands on that advice and urges travelers to treat any last-minute payment request with extra suspicion.
If you think you have been defrauded, reach out to your card issuer to dispute the charges and file a report at ReportFraud.ftc.gov so authorities can track the scam.
Hang on to any shady-looking texts, emails or call logs, and contact your bank and local law enforcement if you were targeted. Louisville viewers with tips can also reach WDRB’s Investigates team at [email protected]. According to the Louisville Metro Police Department's 'File a Police Report' page (louisville-police.org), crimes involving "fraud, forgery, identity theft or criminal possession of a forged instrument" are listed among offenses residents can report. Louisville Metro Police Department pages also explain how to obtain a police report and list contact numbers (Phone 502-574-6857; 502-574-2050), giving residents local routes to report suspected reservation or payment fraud (louisville-police.org).
According to Louisville Tourism's '2023 Year in Review' (gotolouisville.com), 'Louisville's lodging tax remains the primary funding source,' underscoring the significance of visitor stays and why reservation scams could affect many local hotels and diners.









