Cybercriminals exploit trusted travel brands to steal financial data

Phishing sites, fake booking pages and fraudulent compensation offers are increasingly being used to steal financial information from travelers.

 


Cybercriminals are exploiting the trust consumers place in travel brands to distribute malware, steal financial information and carry out online fraud.

A new report identifies the most common attack methods and the travel companies most frequently impersonated in cyber scams over the past year.


Booking a flight, requesting a ride or confirming a hotel reservation can become the first step in a cyber scam. By impersonating trusted travel brands, cybercriminals are distributing malware, creating fraudulent websites and launching phishing campaigns designed to steal banking credentials, payment information and personal data from travelers.

Between the second quarter of 2025 and the first quarter of 2026, Kaspersky solutions detected nearly 262,000 attack attempts impersonating airlines, ride-hailing services and travel booking platforms, highlighting the growing use of these campaigns throughout the travel planning and booking process.

According to the report, attackers rely on phishing websites, fraudulent applications, fake promotions and messages related to reservations or compensation claims to deceive victims. Their objective extends beyond travel information, targeting banking credentials, payment card details, passwords and other personal information.

Most impersonated brands.

Transportation brands accounted for the vast majority of detected activity. During the reporting period, Kaspersky recorded 262,663 detections associated with companies in this sector. Attacks impersonating Emirates represented 61% of the total, while Uber accounted for 37%. Together, the two brands represented 98% of all transportation-related detections.

This concentration suggests that cybercriminals prioritize services with large user bases and high transaction volumes. Consumers’ trust in well-known brands, their search for attractive fares and the frequent switching between apps, websites and devices all increase the likelihood of interacting with fraudulent links or offers.

Trojans were the most common threat, accounting for 30.5% of detections involving transportation brands. This type of malware is typically concealed within files, software or applications that appear legitimate in order to trick users into installing it.

Once installed, it can steal information, download additional malware or provide attackers with remote access to compromised devices. Banking trojans ranked second, representing 22.5% of detections. These threats are specifically designed to steal banking credentials, payment information and other financial data.

Among the campaigns identified was a scam impersonating Ryanair through fake compensation offers for flight disruptions. Victims receive a message claiming they are entitled to a payment and are redirected to a fraudulent website where they are asked either to enter their account credentials or pay a processing fee to release the funds.

The pressure to complete the process before the offer expires is one of the clearest warning signs of fraud.

Travel booking platforms.

Kaspersky also analyzed threats distributed under the guise of travel, accommodation and tourism booking platforms. Between the second quarter of 2025 and the first quarter of 2026, its solutions detected 5,414 attack attempts involving these brands, with trojans accounting for 54.6% of detections.

Accounts on these platforms often contain personal information, payment methods, booking histories and communications with service providers, making them attractive targets for cybercriminals.

Through fake websites or malicious files, attackers seek to steal passwords, compromise payment methods, install malware or gain access to victims’ devices.

One example analyzed by the company replicated the appearance and payment process of Booking.com. Victims entered their personal and financial information believing they were completing a legitimate reservation. However, they never received a confirmation email, the room was never booked and the payment was redirected to the attackers.

In many cases, victims discover the fraud only after arriving at their destination and realizing that no reservation exists.

”This type of fraud is particularly dangerous because it occurs when people are more likely to make quick decisions and share sensitive information. A fake website may appear to be a legitimate booking platform, but it is actually designed to steal passwords, banking information or install malware on a device. In some cases, victims do not realize they have been deceived until they arrive at their destination and discover that the reservation never existed, by which point the money has already been transferred and their personal information may have been compromised,” said Carolina Mojica, Consumer Products Manager for NOLA and SOLA at Kaspersky.

Reducing the risk.

Kaspersky recommends making reservations only through official channels, verifying website addresses before entering personal or financial information, being cautious of promotions that create a sense of urgency and protecting online activity when using public Wi-Fi networks.

The company also introduced Safe Travel Insights, a guide offering recommendations on the digital threats travelers may encounter in different destinations.


Share:
Hosting Web
Most Read