A phishing message used real Booking.com reservation context to push a fake credit card verification page. Reporting it should have been simple. Instead, the official support path led through booking bureaucracy, hidden contact options and finally an email asking for the reservation PIN. After a breach involving customer data, Booking.com appears less like a platform prepared for cyber abuse and more like one still searching for the right department.