Travel Scams Surge as Emirates Tops Cybercrime Targets
Kaspersky detects nearly 270,000 travel-related cyberattack attempts over the past year
As global travel reaches its seasonal peak, cybersecurity firm Kaspersky has warned travelers to stay vigilant against a sharp rise in online travel scams, revealing that nearly 270,000 cyberattack attempts disguised as trusted travel brands were detected over the past year.
According to Kaspersky's latest findings, cybercriminals are increasingly exploiting travelers' reliance on digital platforms for booking flights, accommodation and transportation by creating convincing fake websites, phishing pages and malicious applications.
The research, covering the period from the second quarter of 2025 to the first quarter of 2026, found that Emirates accounted for 61% of all transport brand impersonation attacks, making it the most frequently abused travel brand. Ride-hailing platform Uber followed with 37%, while other targeted brands included Ryanair, Qatar Airways, Lufthansa, British Airways, Turkish Airlines and Skyscanner.
Kaspersky recorded 262,663 cyber threats linked to transport brands during the study period. Researchers found that Trojans represented the largest share of detected threats at 30.5%, while banking Trojans accounted for 22.5%, indicating that attackers are primarily seeking to steal banking credentials, payment information and personal data.
One of the scams uncovered involved fraudsters impersonating Ryanair, falsely informing victims they were entitled to flight compensation. Users were then urged to either provide account credentials or pay a small processing fee before receiving a refund. Kaspersky noted that the scam relies heavily on creating a false sense of urgency to pressure victims into acting quickly.
The company also identified attacks targeting accommodation and travel booking platforms. During the same period, 5,414 cyberattack attempts were detected under the names of popular services including Booking.com, Airbnb, Agoda, TripAdvisor and Viator.
In one example, scammers created a fake Booking.com payment page that closely resembled the legitimate website, convincing users to enter payment information for reservations that never existed. Victims often discovered the fraud only after arriving at their destination and finding no booking on record.
Evgeny Kuskov, Lead Security Researcher at Kaspersky, said travel brands are particularly attractive to cybercriminals because they combine trust, urgency and frequent payment activity.
"People booking flights or rides are often comparing prices across multiple websites while trying to secure the best deal, making them more likely to click on convincing fake offers or account notifications," he said.
To help travelers stay protected, Kaspersky has launched Safe Travel Insights, featuring travel recommendations from employees across more than 20 countries alongside advice on common digital threats encountered while travelling.
The company advises travelers to book only through official websites or apps, verify website addresses before entering payment details, avoid deals that appear too good to be true, enable multi-factor authentication, download apps only from official app stores, regularly monitor bank statements and exercise caution when scanning QR codes or using public Wi-Fi networks.
Related Posts
