The Ertzaintza reportedly recorded 98 complaints tied to hotel-reservation fraud in Spain’s Basque Country from April through September 2026, with losses topping €57,000. Separately, Spain’s cybersecurity institute, INCIBE, warned that scammers can use genuine booking details to make a fraudulent hotel message seem authentic.

Reported cases in the Basque Country

The complaint and loss figures concern the Basque Country and the April–September 2026 period. The reported tally covers hotel-reservation fraud; INCIBE’s alert describes a related phishing method, in which a scammer impersonates an accommodation and tries to lure a traveler to a fraudulent page.

How the hotel-booking messages work

In an alert published July 31, 2026, INCIBE described messages that impersonate a hotel or other accommodation and urge someone with a reservation to confirm or validate the stay through a link. The message may include the property’s name, the guest’s name, stay dates or a reservation number. It may also create urgency by warning that a booking could be canceled.

That information can be accurate and the message can still be fraudulent. The link may lead to a fake page posing as the accommodation or a booking service and asking for personal, identity or payment information. INCIBE also notes that scammers may impersonate accommodations by email or phone.

The Ertzaintza has reportedly cited attacks on booking platforms or accommodation websites, as well as purchases from stolen-data marketplaces, as possible sources of reservation details.

How to check a reservation safely

Go to the accommodation’s official website or app directly, or contact it using details you find independently. Don’t use the link or contact information in an unexpected message to verify the booking. INCIBE lists urgency, requests for sensitive information, an unfamiliar website domain and a sender number that does not match the accommodation’s published contact details as warning signs.

If you opened the link but entered no information, close the page and don’t return to it. If you entered banking information, contact your bank. Keep the message, sender’s number, link, page and any payment records, then report the incident to law enforcement. INCIBE also lists 017 as its cybersecurity help line.