I had a reservation that I made far in advance on booking.com. Last week I received an email from the hotel through booking.com stating that I needed to update my credit card before my stay to maintain my reservation. Included was my name, reservation number and dates of stay. I went to the official booking.com site and there was another message from the hotel stating the same, with a link in the message. I am used to getting messages from hotels on booking.com. Often they are offering taxi service, tours, or requesting approximate arrival time. I clicked on the link in the hotel message (again, on the official booking.com site). It came up with a site that looked like the booking.com page, requesting that I enter my credit card information.
At this point, even with the page looking like booking.com's site, I became uncomfortable entering my info. Scrolling around on the page I could tell that it was a bit different, for example it no longer showed my name as signed in. I then reached out to the hotel independently, and they immediately replied that it was a scam, and to call my bank and cancel any charges. I had not provided my credit card information, so that was not a problem, however I'm still frustrated that I clicked through on the link.
I suspect that it was actually the hotel that had been hacked, not booking.com, since it was part of their messaging? I don't know.
But anyway, hope this makes sense, and just thought I would pass along my experience and maybe it will help someone else avoid being scammed.