US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
The AI race is accelerating faster than the real economy can adapt. Sam Altman concedes adoption is slower than expected, while Nvidia’s record results, Musk’s ambitions, Chinese open models and new jailbreak risks reveal an intensifying contest for compute, influence and control. Across the world.
Brazil is investing US$444 million in AI infrastructure spanning Chinese and US technology. Its strategy avoids dependence on one power, using rival suppliers to build sovereign compute, domestic models and leverage, although genuine autonomy will depend on its energy, skills and strong execution.
14th April 2026 Cyber Update: Booking.com Data Breach Exposes Supply Chain Vulnerabilities as Customers Face Targeted Phishing
Booking.com confirms hackers accessed customer names, emails, addresses, and booking details via third-party compromise. Stolen data is already fuelling targeted WhatsApp phishing attacks, exposing deep supply chain vulnerabilities in global travel platforms.
This image depicts a traveller's nightmare amid recent cyber attacks on Booking.com: a smartphone screen hacked with malware warnings, data breach alerts, and corrupted travel deals, leaving vacation plans in chaos.
Booking.com’s confirmation on 13 April 2026 that unauthorised parties accessed customer booking data marks another serious lapse in safeguarding traveller privacy. The exposed information – names, email addresses, phone numbers, physical addresses, reservation specifics and platform–hotel message histories – while excluding financial details per the company’s statement, has already fuelled a wave of highly targeted secondary attacks.
Affected Australians report receiving WhatsApp messages bearing accurate booking particulars days before official notification, with one Bali traveller losing $100 to a fraudster impersonating Booking.com support.
This is not an isolated failing but a symptom of a systemic vulnerability: security firms Bridewell and Sekoia have long documented how attackers compromise hotel partner credentials via infostealer malware, then mine reservation databases to craft convincing phishing lures. The Dutch Data Protection Authority’s €475,000 fine against Booking.com in 2021 for an almost identical supply-chain breach underscores the pattern.
Why It Matters
The scale of exposure is significant: Operating across 28 million global listings and processing hundreds of millions of bookings yearly, the scale of potential harm is immense. Yet critical questions remain unanswered: how many customers were affected, for how long was data accessible, and through what precise vector? This opacity complicates individual risk assessment and raises concerns about compliance with GDPR and Australia’s Privacy Act, which mandate timely, transparent disclosure of breaches involving personal information.
What Affected Users Should Do
Treat every unexpected Booking.com message as suspect until proven otherwise. Go directly to the official app or website and avoid clicking on links in emails, texts or WhatsApp messages, no matter how authentic they look.
Check your current reservations line by line. Look for any change to guest names, email addresses or phone numbers, which can signal that someone is already inside your account. Turn on two-factor authentication immediately to make it materially harder for attackers to reuse stolen credentials.
Ensure reputable antivirus software is installed and up to date on any device you use for travel bookings, given infostealer malware is a key tool in this campaign. Be wary of unsolicited calls or messages from anyone claiming to represent Booking.com and refuse to share card details, one-time passwords or security codes. Keep a close eye on bank and card statements for unfamiliar transactions, even though there is no firm evidence yet that card numbers were the primary target.
Where possible, route bookings through a dedicated email alias so that a compromise does not expose your main inbox. Do not rely solely on Booking.com’s automatic PIN reset. Log in and update reservation PINs and account security settings yourself to close off easy opportunities for follow-on fraud.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
As artificial intelligence automates both attack and defence, the window to patch critical vulnerabilities is vanishing. Black Hat 2026 research confirms autonomous systems are discovering thousands of previously unreported flaws.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!