
Summer travel security threats are no longer confined to a stolen passport or a skimmed card at a foreign ATM. As technology evolves, and AI puts convincing fraud within the reach of anyone with a laptop, criminals are now targeting travellers before they’ve even packed their bags.
Coined reservation hijacking, a recent Booking.com data breach has enabled criminals to pose as hotels, using real booking details to trick customers into sending money. By referencing genuine check-in dates, names, and hotel information, these scams appear legitimate, wherein fraudsters bypass Booking.com’s systems and contact users directly.
Alongside online holiday phishing scams and fake payment emails, crowded terminals, short connections and unfamiliar surroundings often push people to trust too quickly. Threats including quishing scams and public Wi-Fi traps are capable of turning any dream holiday into a nightmare.
To stay safe when travelling, holiday goers need to build simple digital habits that hold up even when they’re distracted, rushed, or somewhere unfamiliar.
The QR code trap
QR codes are everywhere when we travel: they’re used in airports, restaurant menus, parking meters and ticket kiosks, to name a few. This makes it incredibly easy for a bad actor to put a false QR code over a real one. When scanned, victims will be directed to an outwardly authentic ‘phishing’ site, asking them to input sensitive information like passwords and payment information for seemingly normal reasons.
Placing a QR code in a public space moves the point of attack from the digital world into the physical one. A fraudulent code stuck over a legitimate one on an airport parking meter or an event poster can look like a permanent part of the fixture, and because travellers are usually rushing between places, few stop to check if it’s genuine before scanning.
Quishing attacks also have a structural advantage. They can slip past spam filters and link-scanning tools that catch other forms of phishing, since the malicious payload sits behind an image rather than a flagged URL. Generative AI tools also generate polished fake QR-code pages and convincing follow-up messages in seconds, at both scale and quality.
The public Wi-Fi risk
Public Wi-Fi, whether in an airport, hotel or restaurant, is often unencrypted and sometimes doesn’t even require a password. This makes it easy for bad actors to see what sites users visit or even hijack their sessions. An analysis of public Wi-Fi across Mexico’s 2026 World Cup host cities found that as many as 12% of networks were completely open and unsecured, leaving anyone connected exposed to interception. A fraudster was recently jailed for abusing exactly this. They built evil twin networks at an Australian airport, which are fake hotspots that mimic legitimate networks, and stole people’s login details, data and personal photos.
Despite these risks, avoiding public Wi-Fi altogether isn’t a realistic option for many travellers. Long layovers, delayed flights and expensive roaming charges often leave public networks as the only practical way to get online. While even Google has advised users to avoid public Wi-Fi where possible, travellers can still use these networks safely by taking a few simple precautions.
-
Choose a VPN that doesn’t keep logs
The first line of defence on public Wi-Fi is a VPN. Working like a private and secure tunnel for your internet traffic, everything you send and receive travels encrypted, so anyone else sharing that network sees scrambled data instead of your personal data or activity.
On public Wi-Fi, your activity can be visible to anyone with the right tools, but once the VPN is on, your data travels inside the tunnel. People on the same network, whether it’s hackers, hotspot owners, or even your internet service provider, only see scrambled traffic, not your personal information.
A well-designed free VPN, that doesn’t record logs, can offer the same core protection as a paid one, which is important for travellers on a budget.
-
Lock down your device before you connect
It’s important to assume that everyone else on a public network shares the same digital space you do. A few setting changes include turning off any automatic connections to open networks, so your phone can’t quietly join a fraudulent hotspot in the background.
This also means disabling file and printer sharing on laptops, so your device isn’t discoverable to strangers nearby and also installing any pending software updates before you leave, as most of them exist specifically to patch known vulnerabilities.
-
Treat public Wi-Fi as read-only
Even with these protections, public Wi-Fi can carry risks such as phishing pages or malware. That’s why it’s important to treat public wifi like a “read-only mode,” using it only for searching the web or replying to an email, but avoiding banking and shopping. By restricting activity on these networks to low-risk tasks, people are more likely to keep their sensitive data out of reach, even if the network itself turns out to be compromised.
-
Don’t overlook the basics
Most of the damage still comes down to ordinary bad habits. Weak, reused passwords remain one of the biggest openings travellers leave for criminals and without multi-factor authentication switched on, a weak password can be cracked in seconds.
Also, people click links and open attachments from unfamiliar senders, or from messages imitating a bank, airline or hotel, without pausing to check. As AI advances, those messages are only getting harder to spot; the typos and clumsy phrasing that used to give scams away are disappearing and are now replaced by fluent, personalised messages built to look exactly like the real thing.
Ultimately, by choosing a secure VPN, locking down devices before departure, treating public Wi-Fi as read-only, and staying alert to convincing scam messages, holidaymakers can stay a step ahead of the fraudsters targeting them.


