A new scam is exploiting holiday photos posted on social media, with fraudsters using artificial intelligence to analyse images and craft phishing emails that can steal bank account details. The Guardian reports that criminals can use AI to examine pictures uploaded to Instagram and Facebook, determine where they were taken, and then use that information to make fraudulent messages appear highly legitimate.
AI identifies locations in 91% of travel images
Research from cybersecurity firm McAfee tested more than 21,000 travel images using two freely available AI models. One model correctly identified the location in 91% of cases, while the other reached 87%. Crucially, the images did not need location tags or embedded metadata for the AI to work out where they were taken.
The findings highlight how easily publicly shared holiday photos can be exploited. According to the report, even without explicit geolocation data, the visual content of the images—such as landmarks, signage, or scenery—provides enough clues for AI to pinpoint the location.
Experts advise delaying holiday photo posts
Varun Mirchandani, from Digital Trends, advises: "The simplest precaution is also the most annoying: consider waiting until the trip is over before posting holiday photos publicly, or at least limit them to friends and family."
He adds: "And if a message claims that a bank account or card has been compromised, don't click its link, no matter how convincing it looks. Contact the bank directly through its official app, website, or the number on the back of the card instead."
Tyler McGee, head of Asia Pacific and Japan at McAfee, warned: "While private photos are naturally more protected, it's important to remember that anything shared publicly could potentially be viewed, collected and analysed by bad actors."
McGee added: "Even if the scammer's information isn't perfectly accurate, mentioning a place you've visited can lower your guard and make the message seem legitimate."
Avoid posting boarding passes and live locations
Professor Dali Kaafar, executive director of the Macquarie University Cyber Security Hub, told the Canberra Times that photos of boarding passes and real-time locations should never be uploaded to social media. "Posting while you're still away is effectively announcing that your home is empty, and it reveals your live location," he explained.
The scam comes as millions of holidaymakers prepare to share photos from summer trips. Security experts recommend reviewing privacy settings on social media accounts, limiting photo visibility to trusted contacts, and being cautious of any unsolicited messages referencing recent travel.
If a suspicious email or message arrives claiming a financial issue, the safest course is to avoid clicking any links and instead contact the bank directly through official channels. The research underscores that even seemingly harmless holiday snaps can be turned into tools for cybercrime.



