Travel fraud shifts to trusted platforms as cybercriminals target summer holidaymakers
New research suggested fraudsters are increasingly exploiting legitimate booking systems and verified accounts
Cybercriminals are increasingly targeting trusted travel platforms, verified accommodation accounts, and legitimate booking channels as they seek to exploit the summer travel season, according to new research based on dark-web monitoring.
The findings, published by travel eSIM provider Saily using intelligence from cybersecurity platform NordStellar, indicated that fraud activity linked to travel bookings had become more sophisticated, with criminals moving away from traditional fake websites and towards compromising legitimate accounts and communication systems.
Among the most notable trends was a sharp increase in discussions relating to Airbnb scams. Researchers reported that references to such scams on dark-web forums and Telegram channels had risen almost 30-fold compared with levels recorded during the first half of 2023.
Rather than relying solely on fake accommodation listings, criminals were increasingly focusing on hijacked host accounts, allowing fraudulent properties to be advertised under profiles that already carried reviews, booking histories, and verification badges.
The report also highlighted growing concern over compromised hotel booking accounts. In these cases, fraudsters gained access to hotel-side systems and used legitimate messaging channels to send travellers fraudulent payment requests after reservations had been made.
Because the messages appeared within established booking conversations, they were often more difficult for consumers to identify as fraudulent than traditional phishing attempts.
Researchers further identified increased activity involving fake travel eSIM stores, public Wi-Fi interception schemes, and services offering deepfake identity verification tools designed to bypass security checks on travel-related platforms.
The study said at least 15 travel-specific scam methods or tutorials had appeared on underground forums between January and May 2026, reflecting what researchers described as a growing professionalisation of travel-related cybercrime.
The trend highlighted the evolving nature of fraud risks facing policyholders abroad. While travel scams have traditionally centred on counterfeit websites and advance-payment fraud, the growing use of compromised legitimate accounts could make fraudulent activity more difficult to detect and potentially increase claims linked to financial loss, identity theft, and disrupted travel plans.
The findings were based on an analysis of NordStellar's dark-web and Telegram monitoring dataset covering the period from January 2023 to May 2026.
Researchers examined discussions relating to accommodation fraud, hotel booking scams, and other travel-related criminal activity to identify emerging trends ahead of the peak summer travel season.
The report cautioned that raw discussion volumes should be treated as indicators of direction rather than precise measures of criminal activity, noting that some online channels routinely generated large volumes of spam content that could inflate overall counts.
At ITIC Americas 2026 this week, delegates heard that fraud is increasingly driven by exploitation of trust rather than obvious deception, with criminals taking advantage of consumers' belief that recognised brands, verified accounts, and established platforms are inherently safe.