What Happened
This week, Booking.com confirmed that unauthorized third parties accessed reservation data belonging to a subset of customers. Exposed fields included full names, postal addresses, booking dates, email addresses, and phone numbers. Booking has stated the core platform was not compromised — the access was traced to a third-party service operating in the booking workflow.
Why Vendor-Chain Breaches Keep Happening
The pattern is now familiar. A SaaS platform invests heavily in its own controls, ships SOC 2, gets pen-tested annually, and locks down its perimeter. Then a vendor — a notification provider, a payments aggregator, a customer-success tool, a translation service — gets compromised, and customer data leaks anyway.
Three things drive this:









