
A seasonal rental or accommodation offer displayed online can feature real photos, a real establishment name, and a price consistent with the market, while still being fraudulent. The reliability of a booking offer relies on a set of verifiable signals before any payment: the seller’s identity, the technical consistency of the site, contractual terms, and the payment methods offered.
Reservation Hijacking: The Game-Changing Threat
Classic scams (fake sites, fictitious ads) are well-known. A more recent threat is less recognized: reservation hijacking after platform hacking. Since 2024, phishing campaigns have targeted travelers immediately after they finalize their booking, exploiting their real data (name, dates, hotel, amount paid).
Recommended read : Understanding the stakes of business digitalization: challenges and opportunities to seize
The fraudster poses as the establishment or platform and requests a “payment confirmation” via a page that mimics the official interface. Several European authorities have reported a significant increase in this type of attack.
The direct consequence: the presence of accurate information about your reservation no longer proves that the message is legitimate. An email or in-app message that mentions your name, dates, and hotel can still be fraudulent. Before clicking on a link received after booking, it is possible to verify an offer on Xikori with Netscope to cross-check the displayed information with independent sources.
You may also like : How to find the issue date of your driver's license after losing it?
The basic rule: never re-enter your banking details from a link received via message. Manually return to the site or app where the booking was made and check from your personal space if any action is actually requested.

Legal Mentions and Seller Identity: Technical Checks
The first layer of control is documentary. Any booking site operating legally in Europe must display legal mentions including the company name, registered address, registration number, and contact (email or form). The absence of this information is enough to dismiss an offer.
When these mentions exist, they deserve to be cross-checked:
- The postal address can be verified via a mapping service. If it points to a vacant lot or a residential area unrelated to the declared activity, doubt is legitimate.
- The company’s registration number can be searched in the official registers of the relevant country to confirm that the company is active.
- The site URL should logically relate to the activity. A domain name unrelated to the products or services offered is a warning sign.
These checks take a few minutes and filter out the majority of gross fraudulent sites.
General Terms and Cancellation Policy: Read Before Paying
The general terms of sale (GTS) are not just decorative text. They constitute the contract that frames the transaction. Two points deserve careful reading before any booking.
Cancellation Policy and Hidden Fees
An offer may display “free cancellation” in large letters while specifying in the GTS that this free cancellation only applies after a certain period, or that it excludes processing fees. The actual cancellation conditions are in the GTS, not in the promotional banner.
Also check the mentions regarding supplements: tourist tax, cleaning fees, deposit, parking. An abnormally low price often hides additional fees not included in the displayed rate.
Right of Withdrawal and Tourist Services
Services for accommodation, transportation, or leisure booked for a specific date generally do not benefit from the right of withdrawal applicable to traditional online commerce. This exception, provided for by the consumer code, means that the booking can be firm as soon as confirmed. Understanding this point before clicking “pay” avoids fruitless disputes.

Payment Methods and Transaction Security
The payment method offered by a site says a lot about its reliability. Here are the signals to watch for:
- A site that only accepts bank transfers or prepaid cards and refuses traditional credit cards presents a high risk. Card payments offer dispute mechanisms (chargeback) that are absent from bank transfers.
- The payment page must display the HTTPS protocol with a valid certificate. The absence of a padlock in the address bar indicates a lack of encryption for transmitted data.
- Reliable platforms use recognized payment providers (Stripe, Adyen, PayPal, 3D Secure banking systems). If the payment page redirects to an unknown form without clear identification of the provider, it’s better to abandon the transaction.
Never save your banking details on a site used for the first time. Some browsers or password managers offer virtual cards for one-time use, which limit exposure in case of site compromise.
Online Reviews and Reputation: What They Show and What They Hide
Consulting reviews remains useful, provided you know what you’re looking for. An establishment with only maximum ratings and vague comments (“great stay, I recommend”) published over a short period presents a suspicious profile.
The most informative reviews are those that describe a specific detail (noise, condition of the bedding, discrepancy between photos and reality). Their presence on several different platforms enhances credibility. An accommodation that cannot be found outside of a single site deserves increased vigilance.
Cross-checking at least two independent review sources reduces the risk of relying on fabricated comments. Search engines also allow you to check if the establishment’s name is associated with scam reports.
The reliability of an online offer never rests on a single criterion. It is the accumulation of consistent signals (verifiable legal mentions, readable GTS, secure payment, cross-checked reviews, absence of pressure for urgency) that distinguishes a solid offer from a well-constructed trap.