Professor
Professional
- Messages
- 1,636
- Reaction score
- 1,688
- Points
- 113
The Carder's Complete Guide to Booking and Liquidating Accommodations
Bro, you've hit on a topic that's experiencing a true renaissance in 2026. Hotels and apartments aren't just places to stay — they're liquid assets you can convert into cash with minimal loss if you know the game.According to dark web research, hotel bookings rank as the most common service offered by fraud travel agencies, accounting for 18.2% of all services sold, followed by flights at 13%, with Airbnb and car rentals also present. The market is mature, the margins are real, and the opportunities are expanding.
But 2026 isn't 2020. The game has changed. There's a powerful new attack vector — Reservation Hijacking — that's taken the industry by storm. Let me break down everything you need to know to operate in this space.
TABLE OF CONTENTS
- Why Hotels Are the Perfect Asset for Carders
- The 2026 Hotel Fraud Architecture
- The Buy-For-You (B4U) Model – Dark Web Travel Agencies
- The New Frontier: Reservation Hijacking
- Carding Through Booking.com in 2026
- Non-VBV Cards and Working BINs
- Step-by-Step Hotel Booking Guide
- Liquidating Bookings into Cash
- OPSEC for Hotel Carding – The Three-Tier Architecture
- Carder Checklist
- Common Errors and Fixes
- 2026 Risks and Challenges
- Key Takeaways
1. WHY HOTELS ARE THE PERFECT ASSET FOR CARDERS
Hotels attract carders for several reasons:- High value and instant liquidity. A luxury hotel room can be resold at 30-70% discount for real cash.
- Chargeback difficulty. Once a booking is used, chargebacks become practically impossible.
- Price segment variety. You can work with different cards and different amounts — from budget hostels to luxury resorts.
- AVS bypass. Many booking systems have weak Address Verification System (AVS) checks.
Key factor: Hotel bookings are "card-not-present" (CNP) transactions where the seller never sees the physical card. This is the primary attack vector in the hospitality industry.
"Travel purchases are typically high value and can resemble legitimate spending, they may not be flagged right away on a credit card statement. That gives scammers more time before fraud is reported and the card is canceled." — Marijus Briedis, CTO at NordVPN
2. THE 2026 HOTEL FRAUD ARCHITECTURE
Modern hotel fraud isn't isolated attacks — it's a multi-layered infrastructure.Industry Numbers:
- Target sector: Small and medium businesses—hotels, guesthouses, apartments
- Geography: Germany, France, UK, Italy, Spain, USA — regions with the highest activity
- Scale: At least 350 properties in 50 countries have been caught up in reservation hijacking scams, with peak capacity for around 80,000 guests
The Three Attack Stages:
Stage 1: Data Acquisition- Phishing hotel employees
- Using weak passwords for admin panels
- Buying "fullz" (complete cardholder data) on dark web markets
Stage 2: Booking
- Using stolen cards to pay for bookings
- Using compromised loyalty program accounts
Stage 3: Monetization
- Reselling bookings to customers at a discount
- Money laundering
- Subletting (rental-hopping)
The 2026 Trend: Carders no longer just steal money. They hack hotel systems and communicate with guests through official channels using real booking data. This is called Reservation Hijacking.
3. THE BUY-FOR-YOU (B4U) MODEL – DARK WEB TRAVEL AGENCIES
In 2026, the dominant model is "buy-for-you" (B4U) — carders running "dark web travel agencies".How It Works:
- Client approaches an "agent" on Telegram, Wickr, or TOX.
- Agent takes the order: dates, city, room type.
- Carder (or the agent themselves) uses a stolen card to pay for the booking through a legitimate booking system.
- Completed booking is delivered to the client.
- Payment from the client goes to the agent — usually in cryptocurrency.
Typical Discounts:
- 40-60% below retail price
- Higher-value bookings command deeper discounts
Communication Platforms:
- Telegram – Primary platform; bots for order automation
- Wickr – For more confidential deals
- TOX – For maximum anonymity
How They Operate:
B4U vendors use Telegram groups to run daily operations. They process orders, post listings, use bots, and collect "vouch" messages — public, verifiable feedback from prior orders that functions like reviews — to build reputation.Forums function as advertising hubs where sellers promote B4U services. Escrow is a market-specific trust tool: a third party holds the buyer's funds and releases payment only after a booking is delivered, which reduces disputes.
Red Flag to Watch: Some actors try to bypass escrow to run exit scams where they collect payments from multiple buyers and then disappear without delivering services.
4. THE NEW FRONTIER: RESERVATION HIJACKING
In 2026, a new attack vector has emerged and is actively growing. This isn't just carding — it's complete hijacking of hotel-guest communication."This is really targeted. It's spear phishing targeted to the specific victim with the real details of the reservation." — Luis Corrons, Norton researcher
How the Attack Works:
- Compromise hotel systems (via phishing employees or data leaks)
- Access real bookings – guest names, dates, contact information
- Contact guests through official hotel channels (Booking.com chat, WhatsApp, email)
- Create urgency – "Your booking will be canceled unless you verify payment within 12 hours"
- Steal card data through fake verification pages
The Crucial Campaign Details:
Security researchers have identified a long-running campaign targeting Booking.com partners since early January 2026.Phishing Kit Characteristics:
- Uses dedicated phishing kits designed to mimic the Booking.com brand
- Part of the BR-UNC-030 intrusion set tracked by security researchers
- Developer appears to be of Russian origin (code comments include Russian error messages)
Domain Patterns to Recognize:
| Type | Domain Example |
|---|---|
| Partner phishing | worldweb-mgmnts-app[.]com, webhome-mngr[.]com |
| Customer phishing | Booking.com brand mimics |
| Hosting behind Cloudflare captcha | Standard evasion technique |
The Scale:
- 80,000 euros generated from a single ghost property listing in Milan
- 532 reported cases in the UK with £370,000 in losses (June 2023-September 2024)
- 112 complaints in Hungary with €440,000 in losses
Why It's So Effective:
Traditional phishing detection fails because:- The message comes through official channels the hotel used before
- It contains real booking data – name, dates, order number
- Urgency is created: "if you don't confirm within 12 hours, the booking will be canceled"
- AI-generated content eliminates spelling errors and poorly designed pages
Spot the Difference:
| Indicator | Legitimate | Phishing/Hijack |
|---|---|---|
| Domain | booking.com | booking-payment-update.com, reservation-confirm-booking.com |
| Card request | No after confirmation | Yes — CVV, expiry, 3DS code |
| Urgency | No | "Within 12 hours" or "today" |
| Contact method | In app/on site | WhatsApp, external links |
For the Carder: If you can access a hotel partner account, you can use it to create legitimate-looking bookings with stolen cards and resell them. This dramatically increases the trustworthiness of the booking.
5. CARDING THROUGH BOOKING.COM IN 2026
Booking.com is the prime target for hotel carding. In 2026, two main schemes are actively used.Scheme A: Direct Booking Carding
How It Works:- Find a hotel on Booking.com with a 2D gateway (no 3D Secure required).
- Use a Non-VBV card for payment.
- Get booking confirmation.
- Sell the booking to a client or use it yourself.
Scheme B: Partner Account Hijacking
Since early 2026, an active phishing campaign has targeted Booking.com hotel partners.The Attack Chain:
- Phish hotel employees – emails with "complaints" or booking inquiries using fake domains
- Steal credentials – employee enters details on a fake page
- Take over hotel account – access to Booking.com partner account
- Contact guests – using real booking data through WhatsApp or other messengers
- Steal card data – guests are told their booking will be canceled unless they "verify" payment
Warning: Booking.com itself denies a direct security breach on its platform, pointing to security gaps in individual hotel systems.
"We continue to strengthen our defenses to reduce risk and limit opportunities for bad actors to target our accommodation partners and our customers, and we are seeing results." — Booking.com spokesperson
For the Carder: Partner account access gives you legitimate booking infrastructure. You can use it to create authentic-looking bookings with stolen cards and resell them. This dramatically increases booking trustworthiness.
6. NON-VBV CARDS AND WORKING BINs
Your success depends on choosing the right card. Understanding BINs (Bank Identification Numbers) is critical.What is a Non-VBV BIN?
A Non-VBV BIN is a Bank Identification Number associated with card ranges that do not trigger additional SMS or OTP verification steps during online checkout. These BINs are typically concentrated in a few key segments:| Segment | Characteristics |
|---|---|
| Commercial and Corporate Cards | Issued primarily for business expenditure with higher velocity limits |
| Prepaid and Digital Card Ranges | Frequently issued without 3D Secure enrollment |
| Regional Exceptions | Banks in jurisdictions where two-factor authentication isn't universally required |
Card Types for Hotel Carding:
| Card Type | Features | Best For |
|---|---|---|
| CC CLASSIC | Classic BINs, price $15-50 | Budget hotels, hostels |
| CC HIGH | Premium cards, price up to $50 | Mid-range and luxury hotels |
| CC BUSINESS | Business cards, price $50+ | Expensive hotels, long bookings |
| Non-VBV cards | No OTP required | All hotel types (most profitable) |
Using a Non-VBV BIN Checker:
To achieve optimal accuracy, input the first 6 to 8 digits of the card number. The system will return a classification:- Higher Likelihood – Business, Corporate, or Prepaid designations tend to show lower authentication rates
- Moderate Likelihood – Platinum or Signature products from regional credit unions may produce mixed outcomes
- Lower Likelihood – Standard Consumer or Classic cards from major UK, EU, or US institutions almost always enforce 2FA
Important Distinction:
"No visible authentication challenge" and "no security" are not the same thing.
A transaction may appear frictionless because:
- The merchant and issuer support modern 3DS
- The transaction appears low-risk
- The customer has an established relationship with the merchant
- The device or account has trusted characteristics
- The issuer determines additional authentication is unnecessary
What To Avoid:
- Cards with small balances — useless for expensive bookings
- Cards already used — marked by fraud monitoring systems
- Cards with VBV (require OTP) — unless you can intercept the code
- CC SPARKASSEN — this German bank has a powerful anti-fraud system and small balances
Testing a BIN:
- Use a BIN checker to get information about the bank and card type.
- Test with a micro-transaction ($1-5 donation to charity) to see if 3D Secure triggers.
- If it doesn't trigger — Non-VBV, working BIN.
7. STEP-BY-STEP HOTEL BOOKING GUIDE
Step 1: Infrastructure Setup
- Set up an antidetect browser (Octo, Linken Sphere, Indigo)
- Purchase a residential proxy (IP must match the card's region)
- Create a fresh account on Booking.com or another aggregator
Step 2: Hotel and Aggregator Selection
- Look for hotels through aggregators with 2D gateways
- Avoid sites with strict 3D Secure verification
- Consider hotels with "pay at check-in" option — sometimes weaker verification
Step 3: Card Selection and Testing
- Choose appropriate card class for the booking amount
- Test the card with a micro-transaction
- Check the BIN through a BIN checker
Step 4: Booking
- Fill in card details in the payment form
- If OTP is requested — stop (this is a VBV card, not suitable)
- Get booking confirmation (number and PIN)
Step 5: Liquidation (if you're a B4U agent)
- Sell the booking to a client at 30-70% discount
- Payment in cryptocurrency
8. LIQUIDATING BOOKINGS INTO CASH
Method 1: Reselling to Clients
- Find clients through Telegram channels, forums, acquaintances
- Offer 30-70% discount from market price
- Receive payment in cryptocurrency
Method 2: Subletting (Airbnb)
- Book Airbnb long-term
- Sublet daily on other platforms
- Profit = difference between rental cost and sublet income
Method 3: Dark Web Travel Agency
- Offer booking services with deep discounts
- Operate through Telegram, Wickr, TOX
- Use escrow services for deals
9. OPSEC FOR HOTEL CARDING – THE THREE-TIER ARCHITECTURE
Structured OPSEC frameworks are now standard for high-volume operations.The Three-Tier Architecture:
| Tier | Function | Key Requirements |
|---|---|---|
| Public Layer | Exposure | Clean devices, residential IPs rotated every 48 hours, separate identities, isolated browsers |
| Operational Layer | Execution | Encrypted containers, dedicated infrastructure, hardware-backed key management, complete isolation from public layer |
| Extraction Layer | Monetization | Isolated systems with dedicated cashout channels, airgapped when possible, no cross-contamination |
Core OPSEC Rules:
- Use residential proxies only. Data center IPs are easily detected.
- Antidetect browser. Spoof canvas fingerprint, WebRTC, user agent.
- Clean up after each operation. VM or antidetect must be fully cleared.
- Test cards. First test on micro-transactions.
- New accounts for each order. Each order gets new account, new email, new proxy.
- Never reuse an account.
What Triggers Fraud Monitoring:
- High-value bookings from new accounts
- Geolocation mismatch (IP doesn't match card region)
- Frequent failed payments from proxy networks
- Anomalous loyalty point activity from long-inactive profiles
Modern detection systems examine:
- Device intelligence – unexpected device changes
- Behavioral analysis – transactions that differ from established patterns
- Geographic signals – location inconsistent with account activity
- Velocity checks – unusual transaction volume in a short period
- Account history – known vs. newly created accounts
10. CARDER CHECKLIST
| # | Item | Status |
|---|---|---|
| 1 | Antidetect browser configured (Octo/Linken Sphere/Indigo) | ☐ |
| 2 | Residential proxy purchased and verified | ☐ |
| 3 | Fresh Booking.com account created | ☐ |
| 4 | Card selected for booking amount | ☐ |
| 5 | BIN verified (Non-VBV, not Sparkassen) | ☐ |
| 6 | Card tested with micro-transaction ($1-5) | ☐ |
| 7 | Hotel selected with 2D gateway | ☐ |
| 8 | Payment completed, confirmation received | ☐ |
| 9 | Booking verified on hotel/airline site | ☐ |
| 10 | Client found (if B4U) | ☐ |
| 11 | Payment received (cryptocurrency) | ☐ |
| 12 | All operation traces cleared | ☐ |
11. COMMON ERRORS AND HOW TO FIX THEM
| Error | Why It Happens | How to Fix |
|---|---|---|
| Card fails payment | VBV BIN or insufficient balance | Check BIN, test with micro-transaction |
| Booking canceled | Hotel or aggregator suspected fraud | Use Non-VBV cards with higher limits, check OPSEC |
| Proxy blocked | Data center IP used | Use residential proxies only |
| Account banned | Account or IP reused | Create new account for each order, rotate proxies |
| Client doesn't pay | No escrow or trust | Use escrow services, work with verified clients |
| Fraud system triggered | Anomalous behavior (speed, geolocation) | Randomize behavior, implement delays, use different proxies |
12. 2026 RISKS AND CHALLENGES
1. Booking.com and Aggregator Control Tightening
The active phishing campaign since early 2026 has forced Booking.com to strengthen security. The platform now actively monitors suspicious logins and requires MFA from hotel partners.2. AI Fraud Detection
In 2026, AI is used to detect:- Automated bots for mass account registration
- Unusual booking patterns
- Links between compromised accounts
3. Dark Web Travel Agency Crackdown
Platforms are implementing new fraud controls (tokenization, MFA), forcing carders to adapt.4. Rising Reservation Hijacking
The new hijacking scheme is actively used and makes it harder to distinguish legitimate requests from fraudulent ones. Traditional phishing detection methods no longer work because messages come through real channels with real data.5. Payment Method Shifts
Crypto and cash apps dominate payments because they settle quickly and are harder to trace — but this also means you're at risk of exit scams if you don't use escrow.13. KEY TAKEAWAYS
Bro, hotel carding in 2026 is a complex but potentially highly profitable niche.Golden Principles:
- Dominant model is B4U. You book a hotel with a stolen card and sell it to a client at 30-70% discount.
- Reservation Hijacking is the new vector. Carders hack hotel systems and use real booking data to steal card details.
- Booking.com is the primary target. The 2026 phishing campaign provides new opportunities for hotel account hijacking.
- Traditional phishing detection doesn't work anymore. Messages may contain real booking data and come through official channels but still be fraudulent.
- Non-VBV cards are essential. Without them, you won't get past the first stage.
- OPSEC is your best friend. Clean proxies, antidetect browsers, testing — essential for survival.
- The cat-and-mouse game continues. As platforms close old vulnerabilities, carders adapt — acquiring new data, innovating automated scripts, and attacking less protected APIs.
FINAL WORDS
If you're ready to invest in infrastructure, study the market, and work systematically — you have a chance. But be prepared: this isn't quick money. It's a long-term strategy requiring constant adaptation to new defenses."The common factor is that carders are weaponizing real reservation context and pushing travelers into a fake verification or payment flow." — Luis Corrons, Norton
The game has changed, but the fundamentals haven't. If you have a Non-VBV card and a 2D gateway, you're in. Everything else is optimization.
What's new in 2026:
- Reservation hijacking is your most powerful new tool
- AI fraud detection is getting smarter
- Europol is now involved
- Dark web travel agencies are increasingly sophisticated
What remains the same:
- Non-VBV BINs are still the foundation
- Clean OPSEC is still non-negotiable
- B4U model still dominates
- P2P crypto liquidation is still the cleanest exit
Stay clean. Stay fast. Stay simple. And never stop learning.
The carders who survive in 2026 are those who adapt faster than the defenders. Are you one of them?