Fraudsters are using artificial intelligence to analyze vacation photos shared on social media, then sending targeted phishing emails claiming suspicious activity in those exact locations to steal banking credentials.
A new breed of scam exploits the casual habit of sharing holiday snapshots online. Criminals scrape vacation photos from Instagram and Facebook, use AI to identify the location, then craft convincing phishing messages referencing that specific place.
The attack works like this: You post photos from Porto showing recognizable landmarks or scenery. Within days, you receive a text or email from what appears to be your bank stating "We detected unusual activity while you were travelling in Porto – please verify immediately." The message includes a link prompting you to confirm your card details or account access.
Because the scammer knows your exact location from your photos, the message feels legitimate. The urgency and specificity bypass typical skepticism, making victims more likely to click through and hand over sensitive information.
How to protect yourself:
- Review privacy settings on social media accounts. Disable location tagging and limit who can see your posts.
- Avoid posting vacation photos in real-time. Wait until after you've returned home.
- Be skeptical of unsolicited security alerts. Legitimate banks won't ask you to verify details via text or email links.
- Contact your bank directly using a phone number from their official website, not from any message you receive.
- Watch for generic greetings and poor grammar in suspicious messages—red flags that often indicate phishing attempts.
This scam represents a shift in social engineering tactics. Rather than generic mass phishing, criminals now use readily available AI tools to personalize attacks at scale, making them substantially more convincing.
Financial institutions warn customers to remain vigilant about what they share online and to verify any security alerts independently before responding.
Cryptocurrency hardware wallet provider SafePal disclosed a data breach affecting nearly 40,000 customers after a vulnerability was exploited to steal order information. A threat actor is now selling the compromised data.
Google has built theft-detection features into Android to help protect your phone. Activating these settings can prevent unauthorized access if your device is stolen.
Cloudflare automatically adds analytics tracking to websites when users switch their nameservers to the service, requiring manual opt-out rather than opt-in. The discovery has raised concerns about consent and privacy practices.
French Prime Minister Sebastien Lecornu will hold a crisis meeting Monday to address a cyberattack on France's tax collection agency disclosed last week. The breach compromised approximately 678,000 individual and business accounts.