Feed aggregator
Travel scams are everywhere. Here’s how to avoid them
Planning a holiday should be exciting, fun, and not a cybersecurity risk. But booking flights, hotels, and rental properties often means sharing sensitive personal and financial information across multiple platforms. Combined with frequent travel scams and recurring data breaches in the travel and hospitality sector, it creates plenty of opportunities for criminals.
This guide covers the most common risks when making travel reservations and explains how to avoid them. Save the adventure for your destination.
Travel bookings combine high-value payments with urgency and emotional decision-making. Attackers love that for several reasons:
- Large upfront payments make scams profitable.
- Booking confirmations often contain valuable personal data, such as names, travel dates, contact details, and sometimes passport information.
- Travelers are more likely to act quickly and overlook red flags.
- Travel and hospitality companies are frequent breach targets due to complex IT environments and third-party integrations.
Recent years have seen repeated breaches involving hotel chains, booking platforms, cruise operators, and airlines, exposing everything from email addresses to passport numbers.
Common travel-related scams Fake booking websitesAttackers create convincing clones of airline, hotel, and travel booking websites, often promoted through online ads or SEO poisoning (manipulating search engine results). Victims enter payment details, receive fake confirmations, and only discover the fraud later.
Last year we uncovered a campaign using fake Booking.com websites that tricked visitors into infecting their own devices with a Remote Access Trojan (RAT).
Phishing messages about reservation problemsEmails, texts, or messaging app notifications may claim there’s a problem with your booking and urge you to click a link, open an attachment, or call a number. The scammers often impersonate legitimate travel brands and may include real stolen data from previous breaches.
Earlier this year, we wrote about a Booking.com breach that provided scammers with a lot of useful information that could make their messages appear more convincing.
Vacation rental fraudScammers post fake listings or hijack legitimate ones on rental platforms. They typically encourage off-platform communication or payments to avoid built-in protections.
In 2024, one of our researchers encountered exactly this type of scam. A supposedly legitimate Airbnb listing in Amsterdam turned out to be fake, and the scammer sent an email claiming to be from TripAdvisor in an attempt to collect payment details.
“Too good to be true” dealsDeep discounts on flights or accommodation are used to lure victims into paying for offers that don’t exist.
If a deal seems unusually generous, look for the catch. Be especially cautious when advertisers claim the offer will end very soon. Creating urgency is one of the oldest tricks in the scammer playbook.
Scam or legit? Scam Guard knows. Booking.com impersonation scamsBooking.com has become an increasingly popular brand for scammers to impersonate. According to our—anonymized—Scam Guard data, we’ve recently seen:
- Fake cashback emails promising a €435 refund that lead to phishing websites
- In-app messages requesting an additional reservation fee
- Emails containing PDF attachments that require a “secure viewer,” which turns out to be malware
- WhatsApp messages claiming credit card details are missing and directing users to phishing sites
- Text messages linking to fake Booking.com pages and demanding card verification before a deadline
The number of scams impersonating Booking.com has been growing. Since the breach disclosed in April, Scam Guard data shows a 56% increase in Booking.com-related scams compared to the previous period, with weekly volume up consistently across five straight weeks.
How to book travel safelyThere are a few simple things that can dramatically reduce your risk:
- Use secure payment methods. Credit cards offer better fraud protection than debit cards or bank transfers. Never pay anyone asking for payment in cryptocurrencies or gift cards.
- Stick to trusted platforms. Even though these are not guaranteed to be safe, using them is better than gambling on an unknown platform.
- Don’t click on sponsored search results. I cannot say this often enough.
- Verify the existence of the booked accommodation through other channels.
- Treat requests to move communication or payment to another platform as suspicious.
- Consider urgent language, unexpected attachments, and mismatched sender domains as red flags.
- Downloads needed to open an attachment are not to be trusted. These downloads often turn out to be malware. To block and remove malware, use an up-to-date, real-time anti-malware solution.
Pro tip: Malwarebytes Browser Guard will block known phishing websites and can even recognize suspicious websites that are not in our database yet.
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
WWDC Will Be Tim Cook's Swan Song. I Expect Something Siri-ous
I Spoke With an AI Deepfake Hunter, and Here's What You Should Know
Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown
Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia.
The post Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown appeared first on SecurityWeek.
Attention Economy
Article URL: https://en.wikipedia.org/wiki/Attention_economy
Comments URL: https://news.ycombinator.com/item?id=48396597
Points: 1
# Comments: 1
xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity
Article URL: https://www.wired.com/story/xai-asks-court-to-strip-alleged-grok-deepfake-nudes-victims-of-anonymity/
Comments URL: https://news.ycombinator.com/item?id=48396595
Points: 1
# Comments: 0
New Mystery Submarine Signals China's Rapid Undersea Expansion
Article URL: https://www.navalnews.com/naval-news/2026/06/new-mystery-submarine-signals-chinas-rapid-undersea-expansion/
Comments URL: https://news.ycombinator.com/item?id=48396536
Points: 2
# Comments: 0
2 Years of Programming Chess Apps: My Lessons
Article URL: https://lichess.org/@/HollowLeaf/blog/2-years-of-programming-chess-apps-my-lessons/PoajTjaa
Comments URL: https://news.ycombinator.com/item?id=48396532
Points: 1
# Comments: 0
Minimal EU AI Act Article 50 (AI Disclosure) Banner in React and Tailwind
Article URL: https://github.com/alfalf09/minimal-eu-ai-act-compliance-banner
Comments URL: https://news.ycombinator.com/item?id=48396522
Points: 1
# Comments: 0
Exploration Got Cheap. Human Review Did Not
Article URL: https://www.fbeeper.com/agentkitten/2026/06/04/Exploration-Got-Cheap-Human-Review-Did-Not/
Comments URL: https://news.ycombinator.com/item?id=48396504
Points: 1
# Comments: 1
"Family Guy" Creator Seth MacFarlane Class Day – Harvard Commencement 2006 [video]
Article URL: https://www.youtube.com/watch?v=YOBK-xBOFcc
Comments URL: https://news.ycombinator.com/item?id=48396503
Points: 2
# Comments: 1
A thread-safe disk based persistent queue in Python
Article URL: https://github.com/peter-wangxu/persist-queue
Comments URL: https://news.ycombinator.com/item?id=48396500
Points: 1
# Comments: 0
DiffusionBlocks: Training Neural Networks One Block at a Time
Article URL: https://pub.sakana.ai/diffusionblocks/
Comments URL: https://news.ycombinator.com/item?id=48396490
Points: 2
# Comments: 0
LLVM: ZSTD-Compressed Binaries for "Significantly Reduced" Downloads
Article URL: https://www.phoronix.com/news/LLVM-Zstd-Compressed-Binaries
Comments URL: https://news.ycombinator.com/item?id=48396473
Points: 3
# Comments: 0
Autonomous cars will destroy jobs by 2025 (2015)
Article URL: https://qz.com/403628/autonomous-cars-will-destroy-millions-of-jobs-and-reshape-the-economy-by-2025
Comments URL: https://news.ycombinator.com/item?id=48396433
Points: 5
# Comments: 1
Marjane Satrapi, author of 'Persepolis,' dies at 56
Lambda isn't leaking memory, your metrics are lying to you
Article URL: https://engineering.taktile.com/blog/onnx-memory-usage-on-lambda/
Comments URL: https://news.ycombinator.com/item?id=48396417
Points: 2
# Comments: 0
Show HN: A built-in SQLite viewer for verifying your coding agents database work
Article URL: https://lanes.sh/blog/whats-new-v042
Comments URL: https://news.ycombinator.com/item?id=48396416
Points: 4
# Comments: 0
Apple's Overhauled Siri Will Reportedly Run on Nvidia's Blackwell Chips
Article URL: https://www.macrumors.com/2026/06/04/apple-siri-rely-on-google-nvidia-chips/
Comments URL: https://news.ycombinator.com/item?id=48396410
Points: 1
# Comments: 0
Show HN: ssh late.sh - a cozy command-line Clubhouse for computer people
So first, what are we? A Clubhouse inside the terminal, where people can take a break, chill, chat with others all around the globe, listen to music, play some games, or paint on a live artboard :).
ssh late.sh (or use the companion CLI)
That's all. No passwords. No OAuth. No accounts. Your SSH key is your identity.
Honestly, I've been a little nervous to post this. I wanted the Clubhouse to be something I'm genuinely proud of before sharing, and I think we are finally there :)
There is so much here, so I'll really try to focus on the core:
- full-scale chat, mentions, rooms, public and private, DMs, reactions, image previews, full-quality images, icon picker, anything you need
- music, hop into the YouTube booth (WebView using wry) to listen to the community playlist, submit, vote, skip, or listen to 600+ server tracks divided into three categories (lofi, ambient, classical)
- games, single and multiplayer, sudoku, minesweeper, tetris, snake, nonograms, poker, blackjack, chess, and much more. Leaderboards and badges! First truly server-wide game is in the PR!
- live artboard, think r/place but in a TUI, draw, paint, or just enjoy. Daily and Monthly snapshots, check them out here: https://late.sh/gallery
- shop, buy a new fully-dynamic bonsai to take care of, or maybe a new aquarium, fill it with ASCII fish, or what about a new pet to play with? Quests, daily and weekly + streaks to help you win more chips
- news, rss/atom feeds, connect your own, share with others, auto-generated summaries with a nice ASCII thumbnail shared globally
- directories, a dedicated space to showcase your projects, another to build your "work" profile, and it all rolls up into your live web profile: https://late.sh/profiles (someone has already been hired thx to it!), and another one for co-op tools, right now a canvas builder inside the TUI
- and the NEWEST addition, VOICE chat :) without a browser!
This has already grown into a team effort. Amazing people, amazing contributions, amazing vibe.
Big ones in the pipeline: more BBS/full-scale server, real-time games :)
Hop in, take a break and enjoy ;)
Code: https://github.com/mpiorowski/late-sh Landing: https://late.sh Demo: https://late.sh/play License: FSL-1.1-MIT
Comments URL: https://news.ycombinator.com/item?id=48396398
Points: 5
# Comments: 2
