Travellers booking flights, rides and hotels are increasingly being targeted by cybercriminals impersonating familiar travel brands, with nearly 270,000 attack attempts detected by Kaspersky over a 12-month period. The cybersecurity company recorded 262,663 detections linked to attacks masquerading as major transport brands between the second quarter of 2025 and the first quarter of 2026.
Attacks using the appearance of Emirates accounted for 61% of detections associated with the transport brands analysed, while those masquerading as Uber represented 37%. These findings do not indicate that the companies themselves were compromised; instead, cybercriminals are using the appearance and names of established brands to create phishing pages, fake applications and fraudulent offers that look legitimate to unsuspecting users.
Trojans were the most commonly detected threat among files and objects associated with transport brands, accounting for 30.5% of detections, followed by Trojan-Bankers at 22.5%. Trojan-Bankers are specifically designed to steal banking credentials and payment information, meaning travellers responding to a fraudulent booking or account message could expose far more than just their travel details.
One specific scam identified by the cybersecurity firm impersonated Ryanair and told travellers they were entitled to flight compensation. Victims were directed to enter their account credentials or pay a small processing fee to receive the supposed payout, while a countdown timer was used to create extreme pressure to complete the process quickly. Kaspersky warned that such time pressure is a major red flag, as legitimate airline compensation claims never require travellers to make decisions within seconds or pay upfront fees to receive refunds.
Travel and accommodation platforms were also heavily impersonated, although the number of detected attacks was smaller than those involving transport brands. Kaspersky recorded 5,414 attack attempts associated with travel and accommodation service brands between the second quarter of 2025 and the first quarter of 2026. In this specific category, Trojans accounted for 54.6% of all detections.
One scheme copied the appearance of Booking.com and directed victims to a fake reservation page where they were asked to enter personal and payment information. Travellers completing this process received no genuine reservation, with some potentially discovering the fraud only after failing to receive a confirmation or arriving at their destination without a valid booking.
As digital payment integration grows in the travel sector, users should remain vigilant. For instance, Indian UPI payments are now accepted at the Burj Khalifa, and Emirates has introduced options for India-based flyers to pay fares in monthly EMIs. While these legitimate services enhance convenience, they also provide new avenues for scammers to mimic official payment flows, making it essential to verify that payment portals are authentic.
Kaspersky advises travellers to make reservations directly through official websites or applications instead of following booking links received through emails, text messages or social media. Website addresses should be checked carefully before payment information is entered, as fraudulent pages often use domains that closely resemble genuine airline and booking websites. Travellers should also be cautious about unusually cheap deals accompanied by demands for immediate payment, particularly when payment through wire transfers or gift cards is requested.
Strong and unique passwords, multi-factor authentication and applications downloaded only through official app stores can provide additional protection. Bank and credit card statements should be monitored after travel purchases so unfamiliar transactions can be reported quickly. Furthermore, travellers using QR codes should ensure they come from trusted sources and verify website and payment details before proceeding. Public Wi-Fi remains a significant point of exposure, and users should avoid accessing sensitive email, payment services or online accounts through unsecured networks.
Source: Gulf News



















































































