You found the hotel. The price is good. You click the link, the Booking.com sign-in page loads exactly as you remember it, and you type in your email, your password, and your card. Everything looked right. That's the problem: the page was a fake, and the address bar said booking-cn.com, not booking.com.

Why summer is scam season

When millions of people start booking flights and hotels at once, scammers follow the money. And the numbers this year are not subtle.

Security researchers at Check Point found that in May 2026 alone, 47,318 new travel-related domains were registered, up 33% from April and 19% higher than the same month a year earlier. Of those brand-new travel domains, 1 in every 112 was already classified as malicious or suspicious. Not eventually. Already, in the same month they were registered.

Zoom out and the trend is worse. Attacks on the hospitality, travel, and recreation sector have climbed 122% over three years, from an average of 1,032 weekly attacks per organization in May 2023 to 2,291 by 2026. Travel is now a favorite target, and summer is the peak.

A lookalike travel site isn't a "slightly wrong version" of Booking.com or Airbnb. It's a separate address someone else registered, often pointing to a pixel-for-pixel copy of the real sign-in page, built to collect your login and card details the moment you type them.

What the fake sites actually look like

These aren't crude, misspelled pages. Check Point's researchers documented real credential-harvesting sites that reproduce the genuine sign-in flow. The trick isn't in the design; it's in the address. A dash and a couple of extra letters are all it takes to turn a trusted brand into a domain the brand has nothing to do with.

Realbooking.comthe brand's registered domain
Fakebooking-cn.coma dash and "cn" bolted on; a different owner entirely

Here are the specific lookalikes Check Point named in its 2026 research, so you know the shape of the thing:

Fake domainImpersonatesThe trick
bookingni[.]comBooking.comReproduces the real Booking.com sign-in flow to harvest logins.
booking-cn[.]comBooking.comA dash plus a country-looking suffix; localized phishing aimed at Chinese-speaking travelers.
booking-hk[.]comBooking.comSame dash-plus-region pattern, a second regional variant.
airbnb-ca[.]comAirbnbGeo-targeted Canadian Airbnb impersonation site.

The same research flagged fake presale schemes hiding behind flight-search lookalikes like skyscanners[.]shop and skyscanners[.]life, where an added s and an unusual ending do the work. (We write the dots in brackets like [.] so your browser doesn't turn these into live links; never visit them.)

Why a dash is enough to fool you

Your eye reads booking-cn.com and sees the word "booking." That's the whole con. A dash feels official, like a regional edition of a site you already trust. But to every computer on the internet, booking-cn.com is a completely separate address from booking.com, owned by whoever registered it.

The genuine brands do use other endings for regional sites, which is exactly what makes the fakes plausible. The difference is that a real regional Booking.com address is still built on the brand's actual domain, not a look-alike word with a dash and a country code stapled to the front of .com. The only reliable way to tell them apart is to read the address slowly, right to left, before you type anything.

This isn't new, and it isn't slowing down

Last summer told the same story. Check Point's 2025 travel-season research counted over 39,000 new vacation-related domains in May 2025, with 1 in 21 flagged malicious or suspicious, a 55% year-over-year rise. Hospitality-sector attacks that month hit 1,834 per organization weekly. That report named Booking.com lookalikes too, including a fake reCAPTCHA page aimed at property owners and an Airbnb payment-page impersonator.

The pattern repeats every travel season: a flood of fresh domains, a slice of them already dangerous, the biggest names copied first. If you book trips online, this comes with the territory now.

How to check a travel link by hand

  1. Don't click the link in the email or ad. Copy the address instead (long-press or right-click → "Copy link"), so you can read where it actually goes before you go there.
  2. Read the domain from the right. Find the last piece before the first single slash. For a real site that's booking.com or airbnb.com, plain and simple. Anything like booking-cn.com or booking.com-deals.info is a different address wearing the name.
  3. Watch for dashes and tacked-on words. booking-hk, airbnb-ca, skyscanners: a dash, an extra letter, or a region code bolted onto a trusted name is one of the most common patterns in this year's travel-scam research.
  4. When in doubt, don't follow the link at all. Type booking.com or airbnb.com into your browser yourself, or use the official app, and find the deal there.
  5. Or paste the domain into IP Tracker and let it run the comparison for you in seconds.

How IP Tracker helps

IP Tracker is a free Chrome extension. Paste a domain or a full email address into the popup; the free tier gives you 25 checks a day, with no account and no tracking. Only the value you paste is looked up.

For travel lookalikes, it does the boring version of the check above, every time. It compares what you paste against the official domains of more than 120 widely impersonated brands, and it flags near-miss spellings, dashes, and extra words that dress a fake domain up as a trusted one. A domain that exactly matches a brand's official address gets a "verified" note; a close-but-not-real match is flagged as a possible lookalike so you slow down before typing.

Around that, it shows whether Google Safe Browsing (Google's list of reported dangerous sites) has flagged the domain, how many security vendors flag it on VirusTotal, community abuse reports, and the domain's creation date. Since so many travel scams run on domains registered days earlier, a brand-new registration date is a useful supporting clue: if the banner says a "book your dream villa" site was registered a week ago, that's worth pausing over.

What can't it do?

Honesty matters more than comfort here, so four limits worth knowing:

"Not flagged" is not the same as "safe." Every result is a signal for your judgment, not a verdict. IP Tracker names the tricks it can see. It can't click for you, and it won't promise a site is safe.

The best deal in the world isn't worth your login and your card number. When a travel offer arrives with a countdown timer and a link, slow down and read the domain character by character, or get a second opinion that does.

To summarize:

Have a safe, well-booked summer. 😎