Footprints in the sand: how scammers use the topic of foreign trips
Online scammers can use the topic of foreign trips to deceive Russians, experts have warned about this. Tourists are often under stress and in a hurry, and after returning they have a trail of digital footprints, which makes them an ideal target for intruders. For more information about how scammers use the topic of foreign trips, what schemes should be expected at the end of 2026 and how to protect yourself from them, read the "Izvestia" material.
Why is the topic of foreign trips interesting to scammers
The topic of foreign trips attracts scammers primarily because of the huge and vulnerable audience, Ivan Kostenko, an analyst at the cybersecurity monitoring department at Security Vision, explains in an interview with "Izvestia". Tourists are often in a state of stress and haste, and after returning they have a whole trail of digital traces — reservations, tickets, correspondence with hotels, bank card data. All this makes them an ideal target for deception.
—Tourists are interesting to scammers because trips involve financial transactions and the provision of a large amount of personal data that can later be used for criminal purposes," agrees Vitaly Fomin, head of information security analytics at the Digital Economy League.
In particular, according to him, when buying tickets, booking accommodation, applying for insurance and other services, a person indicates their name, phone number, e-mail address, travel dates, itinerary and booking information, and in some cases, passport and payment information. Attackers can use this information for convincing targeted attacks, blackmail, or theft of funds from bank accounts.
What schemes on the topic of foreign trips can we expect at the end of 2026
At the end of 2026, the activation of schemes around New Year's trips and seasonal sales is most likely, predicts Alexander Vurasco, Director of Development at the Solar AURA External Digital Threat Monitoring Center ("Solar" Group). For example, users can be offered flights, tours, and hotel rooms at a significant discount, guaranteed reservations for a scarce option, or urgent payment for the "last available seat." The link will lead to a fake airline, travel agency, or aggregator website.
"A separate group will be composed of messages addressed to people who have already made a reservation,— the source tells Izvestia. — These may be notifications that the payment has failed, the booking will be canceled, you need to re-enter your card details or make a small surcharge.
In addition, according to the expert, letters and messages about flight postponement, refund of money, compensation for delay, baggage payment and confirmation of the passenger's identity are possible. You can also expect fake visa processing services, electronic entry permits, insurance and travel eSIM. In this case, fraudsters can steal not only money, but also passport scans, addresses, phone numbers and other personal data.
In another possible scenario, the attackers may pose as police, customs, financial monitoring or bank officers and report alleged illegal purchases abroad, violations of currency or customs regulations, suspicious card transactions or contact with a prohibited organization. At the same time, the ultimate goal will remain the same: to force a person to transfer money, apply for a loan, install a remote access program, or transfer cash to a courier.
""Another area is fake QR codes: fraudsters send fake electronic visas, insurance or tickets to the victim, where the QR code leads to a phishing site with the requirement to "pay the fee" or "confirm the data," adds Ivan Kostenko. — Attackers also place their QR codes on information desks in hotels, lobbies, parking lots, and entrances to tourist destinations, disguising them as access to Wi-Fi, menus, or guided tours. The person scans the code and ends up on a page where his card details are being lured out.
What "tourist" schemes of scammers have previously been encountered on the Web
Meanwhile, network scammers have tried to use various schemes on the topic of foreign trips before. "As "Sergey Shcherbakov, technical director of the Stakhanovets company, an expert in the field of information security and IT, says in an interview with "Izvestia", among other things, the attackers used the so—called typesquatting - the creation of phishing websites of airlines and booking services with domain names differing by one character. After payment, the booking was invalid.
"There were also phishing mailings on behalf of hotels and airlines requesting confirmation of bank card data," the expert continues. — In addition, cases of fraud have been recorded when renting housing abroad, when intruders used stolen personal data of tourists.
In addition, fake Wi-Fi points at airports are another vector of information collection for intruders," recalls the deputy head of the department of audits and compliance with information Security requirements at the "Ural Center for Security Systems" IT company Ksenia Kuznetsova. Due to the unstable mobile Internet, as the specialist explains, after arrival, people can switch to the airport network to call a taxi or write to their loved ones.
At this point, without checking the exact name of the network, it is easy to become a victim of an Evil Twin attack — to connect to a double hacker point through which their traffic is intercepted or credentials are stolen.
The "tourist" schemes of scammers primarily target people who organize their trips on their own, says Vladislav Shelepov, a GSOC threat analyst at "Gazinformservice". They go through many different services and constantly receive emails about tickets and reservations. "Therefore, "another message from the "hotel" or "visa application center" is easily lost among the real notifications. At the same time, the tricks involving false law enforcement officers are often tied to recently returned tourists.
How to protect yourself from "tourist" fraud schemes
In order to protect themselves from fraudulent schemes on the topic of foreign travel, experts interviewed by "Izvestia" advise to follow certain safety rules. In particular, according to Vladislav Shelepov, in the case of travel, it is useful to make it a rule that any unexpected booking message should be checked where this reservation was created.
— If the hotel has sent a new payment link, it is better to open the service application yourself or write to support through the official website, — the expert notes. —It's the same with tickets and visa centers — do not follow the link from the first message you see, especially if you are in a hurry.
"""If a "policeman" or "FSB officer" calls after returning and begins to talk about problems due to a foreign trip, it is better to end the conversation, especially if there is a suggestion to transfer money to a "secure account" or transfer it to someone," adds the interlocutor of the editorial office. No government check is closed by transferring money over the phone.
When making a call with such threats, you need to hang up the phone and independently call back the official number of the department on whose behalf the call is being made, emphasizes senior Kaspersky GReAT expert Georgy Kucherin. Also, in no case should you tell the caller personal data, SMS codes, or install applications at the request of the interlocutor.
— For additional protection, we recommend using reliable security solutions that will block the download of malicious files and attempts to access questionable sites, — concludes the specialist.
Переведено сервисом «Яндекс Переводчик»