Spread the love

The old travel scam tended to arrive with a spelling mistake, a suspicious promise and all the polish of a handwritten sign taped to a taxi window.

The modern version can know your name, hotel, travel dates, booking reference and the exact amount you are expected to pay. It may arrive through a familiar platform, mention a genuine reservation and warn that the room will be cancelled unless payment is confirmed immediately.

In other words, the booking may be real while the demand for money is criminal.

That distinction is becoming one of the most important security lessons for Australian travellers, travel advisers, hotels and booking platforms. Fraud has moved beyond the obviously bogus bargain. It now feeds on authentic information, trusted brands and the natural anxiety that accompanies an expensive trip.

Australians reported combined scam losses of $2.18 billion across five major reporting and intelligence sources during 2025, an increase of 7.8 per cent from the previous year. Phishing accounted for $97.6 million of those losses.

The national figure combined data from Scamwatch, ReportCyber, the Australian Financial Crimes Exchange, IDCARE and the Australian Securities and Investments Commission. Adjustments were made for duplicate and unreliable reports.

During the first three months of 2026, Scamwatch received 45,816 reports involving approximately $76.7 million in reported losses. ReportCyber separately recorded 15,391 scam-related reports to police, involving reported losses of $187.7 million.

The number of reports and reported losses fell compared with the same period in 2025. However, the Australian Competition and Consumer Commission cautioned against treating a single quarter as proof of an established trend.

There is some good news, then.

The less comforting news is that criminals do not appear to have retired to a seaside villa. They are refining the pitch.

The real booking with the fake demand

The most convincing travel scam no longer begins with a fictional prize or an improbable discount. It begins with information the traveller recognises.

Dozens of Australians told the ABC in June that they had received phishing messages connected with genuine Booking.com reservations.

The approaches arrived via email, WhatsApp and, in some cases, the Booking.com platform. They included traveller names, hotel details, dates, booking references, PINs and payment amounts.

That level of detail removes many of the warning signs people have been taught to spot. There may be no clumsy greeting, no bizarre grammar and no mystery property in a country the victim has never considered visiting.

Instead, the message says the reservation is at risk. A payment must be repeated. A card must be verified. A link must be opened before the room disappears.

Urgency does the rest.

Booking.com warns that phishing messages may include convincing dates, prices and stay details, followed by urgent demands to resubmit payment information.

It says it will never ask customers to provide credit-card details by email, telephone, text message or WhatsApp. It also advises customers to check payment requests against the policy shown in their booking confirmation.

That is the central test. Familiar information does not prove that the person requesting money is entitled to receive it.

A criminal with stolen booking data does not need to invent a plausible holiday. The traveller has already completed that part of the work.

Holiday fraud has many passports

Digital booking fraud is only one part of the threat.

Smartraveller’s current advice covers vehicle-hire scams, taxi fraud, overcharging, card skimming, fake tickets, fraudulent accommodation, visa scams, fake QR codes, carry-my-bag approaches and virtual kidnapping assisted by artificial intelligence.

Each relies on a slightly different weakness.

Scammers can establish fake websites or profiles, post fraudulent accommodation advertisements on genuine platforms and offer ticket or holiday packages that do not exist.

Some third-party visa websites charge travellers to submit applications on their behalf, while others sell unnecessary, illegal or overpriced visas. Some of these services are fraudulent.

Smartraveller advises Australians to apply through links or organisations recommended by the relevant embassy or consulate.

Fake QR-code stickers placed over legitimate codes can direct travellers to fraudulent payment pages. A code that appears to belong to a car park, café or ticket machine may instead collect card details for someone with no intention of providing parking, coffee or anything resembling a service.

The carry-my-bag approach is even more dangerous.

A stranger asks a traveller to take a parcel across a border, perhaps as a favour for a relative. The package may contain drugs or another illegal item.

Good intentions carry very little weight at a customs desk.

Smartraveller also warns about virtual kidnapping and family-in-need scams. Criminals may use material posted on social media to tell relatives that a traveller has been injured, arrested or abducted.

Artificial intelligence can create altered photographs, video or audio to make the story appear genuine.

The traditional postcard said, “Wish you were here.”

The deepfake says, “Send money now.”

Travel data tells criminals when to strike

A holiday produces a rich trail of information.

There are booking emails, passport copies, loyalty accounts, restaurant reservations, boarding passes, flight numbers, hotel check-ins, photographs and cheerful social posts announcing that the family home is empty for a fortnight.

Cybersecurity expert Professor Daswin de Silva has warned that booking data is particularly valuable to criminals because it can reveal details about a traveller’s identity, movements and finances.

That information lets a scammer choose the moment when an approach appears believable.

A traveller waiting for a hotel transfer may trust a message about a driver. Someone expecting a visa approval may respond to a fake immigration email. A passenger whose flight has been cancelled may be relieved when an apparent airline representative offers an immediate refund.

Travel is costly, urgent and often unfamiliar. People make decisions while tired, moving between networks and worried that one missed instruction will destroy the itinerary.

Scammers do not merely target a payment.

They target the moment.

The travel trade is part of the security chain

The industry cannot solve this problem by telling customers to be more careful.

Travel advisers, hotels, tour operators and booking platforms hold detailed customer data. They also communicate about payments, itinerary changes and identity documents.

That makes them valuable targets and trusted identities for criminals to imitate.

Multi-factor authentication should be standard across booking systems, email accounts and office systems.

The Australian Cyber Security Centre describes it as one of the most effective controls an organisation can use to prevent malicious access to services, systems and sensitive data. Phishing-resistant methods should be preferred wherever practical.

Staff also need clear procedures for payment changes.

A hotel should never issue an unexpected bank-transfer request without offering a safe and independent way to verify it. An agency should confirm significant changes through a known telephone number, established customer portal or another trusted channel.

A business that discovers an account has been compromised should warn affected customers quickly. It should explain what information may have been exposed and describe precisely how genuine contact will occur.

Silence leaves a vacuum.

Scammers are excellent at customer communication when the genuine business is not.

The sector must also be careful with language. “Your booking may be cancelled” can be a legitimate operational warning, but it is also the sentence criminals use to force hurried payment.

Good businesses give travellers time to verify a request.

Crooks prefer a countdown clock.

Seven checks before paying

Travellers can reduce the danger without turning every booking into a royal commission.

First, stop when a message creates urgency. A demand for immediate action is a reason to verify, not a reason to hurry.

Second, open the official app or type the known website address into the browser. Do not use the link supplied in the message.

Third, contact the hotel, airline, cruise line or travel adviser through independently verified details. The telephone number inside a suspicious email proves only that the scammer owns a telephone.

Fourth, compare the request with the original confirmation. Check the payment schedule, cancellation terms, currency, recipient and amount.

Fifth, be suspicious of unexpected demands for payment by bank transfer, cryptocurrency or gift card. Such methods can be difficult to reverse and are common warning signs of fraud.

Sixth, activate multi-factor authentication and use a unique passphrase for travel, email and loyalty accounts. A compromised email account can provide access to an entire itinerary.

Seventh, limit what is posted publicly while travelling. The Australian Cyber Security Centre advises against sharing details such as flight numbers, hotel check-ins, location information and photograph metadata.

It also recommends trusted mobile data or a personal hotspot instead of unsecured public Wi-Fi wherever possible.

The airport photograph can wait.

The aircraft is unlikely to take offence.

Visa and document scams deserve special caution

Visa applications are ripe for fraud because rules differ between countries and often use unfamiliar terms.

Before applying, travellers should check official destination advice, confirm whether a visa is actually required and use links recommended by the relevant embassy or consulate.

Some third-party visa services are legitimate. Others charge unnecessary fees or submit fraudulent applications. A fake visa can lead to arrest, detention or deportation at the border.

Passport scans, birth dates and identity papers are not merely forms. In criminal hands, they can support identity theft long after the holiday has ended.

The cheapest visa service can therefore become the most expensive souvenir of the trip.

What to do when the trap closes

Speed matters after a suspected scam.

A traveller overseas should first move to a safe place.

Smartraveller advises victims to report the crime to local police, obtain a police report, contact their bank or financial institution and notify their travel insurer.

Anyone who has sent money should contact the bank immediately using its official telephone number. A fast report may help stop a transaction or secure an account.

Cybercrime involving stolen money, identity or extortion should be reported through ReportCyber. Suspicious approaches should also be reported to the National Anti-Scam Centre through Scamwatch.

People whose identity information may be at risk can seek help from IDCARE.

Passwords should be changed, compromised cards blocked and suspicious account sessions closed. Screenshots, receipts, messages, website addresses and transaction records should be preserved.

Australian consular officers can provide general assistance overseas.

They cannot investigate the scam, report it to local police on the traveller’s behalf, provide legal advice, pay bills or lend money. The Consular Emergency Centre is available around the clock for genuine emergencies.

Embarrassment should never delay action.

Scams are designed by organised criminals who test messages, use stolen information and study how people respond.

Falling for one is not proof of stupidity.

Remaining silent simply makes the next victim easier to find.

Travel advisers have an opportunity to lead

Security is becoming part of the value offered by a professional travel adviser.

A good adviser can verify payment demands, identify dubious visa services, explain booking rules and help when something goes wrong.

That assistance is especially valuable for complex itineraries, older travellers and customers visiting unfamiliar destinations.

Hotels and agencies should add a plain security notice to each confirmation. It should explain how payments will be requested, which communication channels are used and what the business will never ask a customer to do.

That is not alarmist.

It is modern customer service.

The travel industry has spent years perfecting frictionless booking. Its next task is ensuring that convenience does not become an open door.

The deal can wait; verification cannot

Australians should continue to book holidays, explore the world and enjoy the freedom travel provides.

Fear is not a security strategy.

A small pause is.

The best defence is to separate familiar information from the request for money. A correct hotel name, travel date or booking reference may make a message persuasive.

It does not make it genuine.

Stop. Check independently. Protect the account.

A holiday should end with photographs, receipts and perhaps a regrettable airport purchase.

It should not end with the discovery that the only person enjoying the upgrade was the scammer.

 

By: Michelle Warner – © 2026.

Read Time: 9 minutes.

 

Author Bio:
MIchelle Warner - Bio PicMichelle Warner has always carried stories the way others carry passports lightly, faithfully, and with purpose. She learned her craft in newsrooms, shaping sentences with care, before swapping deadlines for departures as a flight attendant with some of the world’s great airlines. Years aloft sharpened her eye for character and deepened her fondness for the small, dignified rituals of travel, the quiet kindness of strangers, the poetry of arrival, the patience learned between time zones.
Now grounded by choice, Michelle has come home to writing with the same calm authority she once brought to turbulent cabins. Her prose blends an editor’s discipline with a traveller’s wonder, tinged with humour and reverence for the golden age of travel. Each piece feels like a handwritten boarding pass, gracious, observant, and unmistakably alive.

 

===============================