Travelers face a shifting landscape of digital deception as scammers increasingly deploy artificial intelligence to craft convincing fake websites and weaponize stolen data, according to Florent Silve, an executive at Engine. This technological shift has replaced traditional pickpocketing concerns with sophisticated online fraud that targets unsuspecting vacationers before they even leave home.
Federal data highlights the scale of this financial threat. According to a Federal Trade Commission report published in June, Americans reported losing $3.5 billion last year to impostor scams involving text messages, emails, phone calls, social media, and search engines. Nearly one in three fraud reports centered on impostors, making it the most reported fraud category.
Reservation Hijacking and Fake Confirmations
Among the emerging threats is reservation hijacking, a tactic where scammers exploit legitimate booking systems to target travelers. Iskander Sanchez-Rola, a scam expert for cybersecurity firm Norton, explains that cybercriminals phish hotel staff to steal login credentials and access real reservation databases.
Armed with actual booking dates and exact stay costs, imposters send emails or text messages claiming a payment failure requires immediate action. “The main thing is that this isn’t a fake booking confirmation, it’s a real reservation that is weaponised against you,” Sanchez-Rola said. Security experts advise victims to bypass links in suspicious messages, visit the official hotel website, and call independently verified numbers.
Flight Cancellation Scams and Social Media Risks
Scammers also manufacture urgency by targeting travelers with fake flight cancellation notices shortly before departure. These messages demand extra fees to rebook canceled or delayed itineraries. Sanchez-Rola recommends verifying flight status directly through the airline’s official portal rather than clicking links in unsolicited texts.
Pro Tip: Never post photos of plane tickets or boarding passes on social media. Barcodes and QR codes contain hidden personal data, including return flight details, which scammers can harvest.
Restaurant QR Code Tampering and Public Wi-Fi Dangers
Physical vulnerabilities still exist alongside digital traps. Alissa Abdullah, Mastercard’s deputy chief security officer, warns that criminals place fraudulent QR code stickers over legitimate restaurant payment codes to redirect funds to malicious accounts. Customers who spot mismatched stickers should request alternative payment methods like cash or credit.

Meanwhile, public Wi-Fi networks present distinct cybersecurity hazards. Brian Cute, CEO and director of the capacity and resilience program at the Global Cyber Alliance, notes that cybercriminals frequently set up fraudulent networks mimicking legitimate public Wi-Fi names. Travelers logging onto these fake networks risk data theft and device compromise. Cute recommends limiting public Wi-Fi usage to basic searches, avoiding sensitive tasks like online banking.
Frequently Asked Questions
What is reservation hijacking?
Reservation hijacking occurs when scammers use stolen hotel login data to access real guest reservations, then send targeted messages demanding payment fixes using accurate booking details.

How can I verify a flight cancellation notice?
Ignore text message links and log directly into the official airline portal or app to check your actual flight status.
Are public Wi-Fi networks safe at airports?
Public Wi-Fi carries risks because criminals can deploy fake networks mimicking legitimate ones; users should avoid accessing banking or personal email accounts over these connections.
Have you encountered a sophisticated travel scam recently? Share your experience in the comments below, explore our archive for more cybersecurity guides, and subscribe to our newsletter for weekly safety updates.
>Related reading